POPULARITY
Categories
Did you know that 82% of all intrusions don't involve any sort of malware, and AI-augmented attacks are up 89% year over year? If your security operations team is solely focused on reacting to known-bad SIEM alerts, you may be missing the silent breaches. In this episode, Ashish is joined by Damien Lewke, Founder and CEO of Nebulock, to discuss the critical shift toward a "Hunt First" mindset. Damien explains why moving away from alert fatigue and focusing on raw, normalized telemetry (across endpoint, identity, and cloud) is the only way to proactively surface unknown threats. We also dive into how AI is finally democratizing the elite skill of threat hunting, allowing even single-person security teams to investigate and attribute complex behaviors.From hunting down shadow AI (like unapproved MCPs) to challenging the notion that AI will replace threat hunters, this episode is a masterclass in modern security operations. Guest Socials - Damien's LinkedinPodcast Twitter - @CloudSecPod If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-Cloud Security Podcast- Youtube- Cloud Security Newsletter If you are interested in AI Security, you can check out our sister podcast - AI Security PodcastQuestions asked:(00:00) Introduction: The Problem with Reactive Security Alerts(02:00) Damien Lewke's Background (DoD, CrowdStrike, Arctic Wolf, Nebulock)(04:00) Why Breaches Happen in Silence: The Value of Telemetry Over Alerts(05:30) How AI Democratizes Elite Threat Hunting for Small Teams(07:30) Defining the "Hunt First" Mindset and Methodology(11:00) Surfacing Active Intrusions Using Cross-Domain Context(13:30) The Importance of Transparency in AI Decision Making(16:30) When NOT to Use AI for Detections (The Power of Heuristics)(18:30) The Best First AI Security Use Case: Hunting Shadow AI & MCPs(23:00) Detecting Rogue AI Agents via Tempo, Breadth, and Automation Signatures(28:30) The Future of SIEM: Data Gravity vs. Purpose-Built Security Analytics(34:30) Disagreeing with Gartner: Why Threat Hunters Are More Vital Than Ever(40:00) The 89% Rise in AI-Augmented Attacks and Taking Action(41:30) The "You Laugh, You Lose" Cybersecurity Joke Challenge Resources spoken about during the episode:- Hunting MCP Server Exploitations- Using classical machine learning for threat hunting (and saving tokens in the process)- Your newest insider has legitimate access
On this week's show Patrick Gray and James Wilson are joined by guest co-host Dmitri Alperovitch to talk through the week's news, including: Trump's memo authorising the private sector to release the cyber hounds is fine, don't worry! OpenAI finally decides to add a few safety measures after the whole “oopsie we committed some felonies” thing Anthropic's models start a turf war when given the same task, surprising… nobody We can't figure out whether a device that can hack a 737 is showboating stunt hacking or … something more real-world cool. Or both. Or something. Much, much more This week's show is brought to you by threat hunt and detection platform Nebulock. Founder and CEO Damien Lewke joins Pat to chat about what it looks like when you try to reinvent the SIEM in 2026 on a clean sheet of paper. This episode is also available on YouTube Show notes Trump signs memo authorizing private sector to launch cyberattacks | washingtonpost.com Trump taps cyber firms to go on offensive against criminals | therecord.media OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue | wired.com Pacing model development in an era of cyber-critical capabilities | Anthropic set AI agents loose on the same task. They started a turf war. | TechCrunch Security Researchers observe first ‘near-autonomous' AI attack on government target in Taiwan | cyberscoop.com Researchers find AI-powered hacking tools for sale in underground forums | Cybersecurity Dive Terabytes of credentials leaked in massive supply-chain attack | arstechnica.com Trivy, Not LiteLLM Behind the 2,500 Org Compromise | securityweek.com Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes | The Record ‘Unprecedented' number of Apple users received recent spyware alert, say investigators | TechCrunch Security This Coin-Sized Device Can Hack a Boeing 737 | wired.com "City-Forum" data-theft attacks target Salesforce, ServiceNow portals | BleepingComputer Max severity SAP Commerce Cloud flaw now targeted in attacks | BleepingComputer Shell investigates 'potential incident' after Clop data theft claims | BleepingComputer Philips and GE investigating Clop ransomware data theft claims | BleepingComputer Uber Freight reportedly investigating after hacking group claims data breach | TechCrunch Security Details emerge on BlackFile's recent attacks on financial companies | cyberscoop.com After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug | TechCrunch Security Kimwolf botnet rebuilt to survive takedowns, researchers say | cyberscoop.com Hundreds of fake Chrome VPN extensions route traffic through a proxy | BleepingComputer Deepfake hiccup unmasks suspected digital certificate fraudster | theregister.com Vulnerability giving attackers full control of Macs is under active exploitation | arstechnica.com Critical VMware vCenter RCE flaw exploited for reverse SSH access | BleepingComputer Poland probes MyDr healthcare software breach potentially affecting 19 million people | therecord.media Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts | TechCrunch Security [un]prompted.au — AI × Cybersecurity Conference · Sydney, 18–19 September 2026 | [un]prompted.au
Brian Dye, Chief Executive Officer at Corelight, spends Black Hat USA 2026 asking every organization he talks to the same question. What are you doing with AI in the SOC? A year ago, he says, teams thought it was a good idea but were wary of it, and people knew LLMs could produce things without being sure what to do with them. Now he is talking with organizations building their own agents for incident response and for threat hunting, and running their own quality control on the output rather than taking it on faith. What decides how far an agentic SOC workflow can go? The data does. Brian Dye describes a three-legged stool where the model and the agents are only two of the legs. The third is the data going into the workflow, and without the right data the agents hit a headroom of logic. He credits three changes for the shift. Agentic development decomposes an investigation into smaller chunks that can be trusted individually. Time in the saddle has made teams better at separating claims from reality. And organizations now ask the workflow itself what it could not answer and what data it wishes it had. Why does a week like this one matter to product development? Corelight works on translating the network into the right fuel for AI, which means understanding the architecture each customer is building toward, whether that is an in-house SOC, a third party SOC, or a workflow running through their own SOAR or SIEM. Brian Dye also describes the Black Hat NOC as a room where the work looks different. Most security teams look for a needle in a haystack. The NOC team is finding the sharp needle in a stack of dull needles, separating illicit activity from the legitimate malware analysis training running on the same network, while using the room as a multi-vendor playground for new integrations and workflows. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Brian Dye, Chief Executive Officer at Corelight On LinkedIn: https://www.linkedin.com/in/brdye/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Corelight: https://corelight.com Corelight blog: https://corelight.com/blog Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS brian dye, corelight, marco ciappelli, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic ai, ai in the soc, security operations center, network detection and response, threat hunting, incident response, black hat noc, soar, siem, network evidence, agentic workflows Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Recorded on site at Black Hat USA 2026 in Las Vegas, Seth Summersett joins Sean Martin to talk through the volume problem that shapes a modern security operations team. Seth Summersett spent about a decade at the NSA and roughly a decade at Mandiant, finishing there as head of innovation and custom engineering, then a couple of years at Meta supporting business unit level CISOs. He co-founded Embed Security with Jeffrey Johns, who ran the data science team alongside him at Mandiant. The catalyst came from watching a managed service run on human scale day after day. Two analysts and a hundred forwarded phishing emails means someone is choosing which ones to open and carrying the ones they cannot reach. Embed Security sits downstream of existing detection investments, taking signals from SIEM, EDR, identity, and email rather than asking a team to rip and replace what it already runs. What do security analysts actually want from AI in the SOC? According to Seth Summersett, it is not a verdict. Analysts want the work off their plate in a way they can verify, which is why Embed Security built what it calls chain of evidence, showing every question asked and the path to each conclusion. Teams also test it in reverse, running previously dispositioned alerts back through the platform to compare results against their own analysts. The numbers come from a competitive bake off at one of the company's largest clients. Embed Security dispositioned roughly 75% of that client's alerts to the point where the team stopped treating them as primary work, against a daily volume above 10,000 alerts. Why not build this in house? Seth Summersett says the demo is the easy part. What follows is evaluation loops that measure a change across hundreds of thousands of alerts rather than one, governance, and a way to capture organizational knowledge automatically. In regulated sectors, auditors may ask a team to prove how a conclusion was reached and that it holds consistently. There is a people side to this as well. Embed Security has supported a wellness program at BSides across its last two events, backing a calming kit and curriculum for analysts working under incident pressure. Seth Summersett closes with consistency for leaders, since a leader looking at 10% of alerts does not have a full risk profile, and career longevity for analysts who would rather build a long run in security operations than burn out in two or three years. GUEST Seth Summersett, Co-Founder and CEO, Embed Security LinkedIn: https://www.linkedin.com/in/summersett/ RESOURCES Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Embed Security: https://www.embedsecurity.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS seth summersett, embed security, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, black hat usa 2026, security operations, soc analyst burnout, alert triage, agentic ai security, chain of evidence, siem alert fatigue, edr alerts, ai soc platform, security analyst workflow, build versus buy security ai, security operations governance, threat investigation Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Recorded on location at Black Hat USA 2026 in Las Vegas at the end of day two, Karthik Kannan, Founder and CEO at Anvilogic, walks through a seven year build that reached its original shape this year. The plan from the start was a full security operations platform covering data, the detection engineering process, triage and investigation, and case management. In the shorthand of the category, SIEM and SOAR combined. It arrived in phases. Detection engineering came first, implemented on top of Splunk for most customers, then the data platform expanded into data lakes including Snowflake, Databricks, and Microsoft Azure. Triage and investigation followed over the last two years. In the last year Anvilogic rolled out agents that carry out the work of specific personas, and this year the company launched Blueprints, an orchestrator agent that brings the discrete agents together to run a whole workflow with humans in the loop. What separates a security graph from a frontier model? It knows the environment. Karthik Kannan describes the enterprise security graph as Anvilogic's own model running inside the network, learning the micro environment, with frontier LLMs called on to fill gaps in the macro environment. His argument is that platforms operating as LLM wrappers miss the last mile, because AI on its own reaches 60, 70, or 80 percent of the way if you are lucky. How does a team keep control when agents run the workflow? Through gates, permissions, and a record of what happened. Workflows can be described in plain English, with human gates inserted as often as the team wants. Access controls sit at the persona, organization, and object levels, and activity is audited and logged, which matters to the GRC teams Anvilogic works with. Screens dedicated to what the company calls a maturity score show which feeds are coming in, what kinds of detections exist, and what coverage looks like against the MITRE ATT&CK framework, in a form available to executives and CISOs. Karthik Kannan also points to version 8.0, introduced the week before the event, which includes an Anvilogic MCP Server for connecting to third party tools. Customers are already building their own Blueprint workflows during proofs of concept, including a large life sciences customer Anvilogic expects to feature in a public case study. Karthik Kannan is careful about the claim being made here. This is not a proclamation of an autonomous SOC. It is automation that makes life in a SOC easier and more efficient, adopted at a crawl, walk, run pace, with every step visible along the way. This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing GUEST Karthik Kannan, Founder and CEO at Anvilogic On LinkedIn: https://www.linkedin.com/in/karthikkannan001/ RESOURCES Black Hat USA 2026 event coverage from ITSPmagazine: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Learn more about Anvilogic: https://www.anvilogic.com Anvilogic 8.0, from onboarding to investigation: https://www.anvilogic.com/learn/anvilogic-8-0-automate-the-soc Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS karthik kannan, anvilogic, sean martin, brand briefing, brand story, brand marketing, marketing podcast, black hat usa 2026, agentic secops, ai soc platform, enterprise security graph, detection engineering, triage and investigation, blueprints orchestrator agent, mcp server, mitre att&ck coverage, human in the loop automation, siem and soar, security operations, grc audit logs Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Today’s headline news for Canadian IT solution providers: [Schneider Electric]: The company yesterday unveiled its next-generation APC Smart-UPS at XChange August 2026, introducing what it says is the first multi-chemistry battery technology for distributed and edge environments. The platform accepts both VRLA lead-acid and lithium-ion batteries, allowing customers to start with lower-cost lead-acid and upgrade later without replacing the chassis. Read more on CRN. [Ingram Micro]: The distributor says hundreds of channel partners are now using its Xvantage Integration Hub and secure Model Context Protocol Server to connect AI assistants directly to their business systems. Trust X Alliance member Matrix Integration estimates the platform will save its team between 1,000 and 1,500 hours this year, while IT Design Consulting says it cut quoting from hours or days to seconds. Read the announcement on Ingram Micro. [D&H Distributing]: The distributor is now authorized to carry Dell Technologies’ full enterprise storage portfolio in the United States and Canada, adding a new sourcing option after Dell ended its relationship with Arrow Enterprise Computing Solutions. D&H says its Advanced Solutions+ business unit now accounts for more than 25 percent of its overall business. Read more on CRN. [Acronis]: The company unveiled an autonomous IT platform update with an AI-driven console, service desk, and migration tools designed to help MSPs automate operations and expand services. Read more on msp-channel.com. [NCC Group and SailPoint]: The two companies have partnered to strengthen identity security services for both human and non-human identities. Read the announcement on NCC Group. [Lexful]: The company announced general availability of its AI-native IT documentation platform for MSPs, with plans to join the Pax8 and Sherweb marketplaces before the end of 2026. Read more on Yahoo Finance. [Circana]: Research presented at XChange August says AI’s workforce shock is unlikely to ease in the near term, with MSP executives noting persistent talent gaps despite automation advances. Read more on CRN. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, August 11, 2026, and here’s what’s happening in the channel today. Schneider Electric yesterday unveiled its next-generation APC Smart-UPS at XChange August 2026, introducing what the company says is the first multi-chemistry battery technology for distributed and edge environments. The new platform accepts both traditional VRLA lead-acid batteries and lithium-ion batteries, allowing customers to start with lower-cost lead-acid technology and upgrade to longer-lasting lithium-ion later without replacing the chassis. Adam Compton, offer management leader at Schneider Electric, told CRN that the chassis is engineered to recognize different battery chemistries through firmware and battery management systems, which then alert EcoStruxure IT monitoring software about the specific battery type and replacement timeline. The company says future battery chemistries will also be supported as they become viable. For channel partners, the flexibility creates new service opportunities around battery lifecycle management, assessment, and the Rip-Replace-Recycle refresh program. Gordon Lord, vice president of channels, said Schneider Electric is doubling down on its Gateway program to give partners visibility into distributed power infrastructure across customer sites. The online versions of the new Smart-UPS are slated to be available starting September 1, with line-interactive versions following next year. Partners will not require new certifications. Canadian partners working with regulated and industrial customers should note the air-gapped deployment potential and the EcoStruxure monitoring layer as a recurring services hook. Ingram Micro says hundreds of channel partners are now using its Xvantage Integration Hub and secure Model Context Protocol Server to connect AI assistants directly to their business systems. The distributor announced the expanded adoption last Wednesday, positioning the platform as a way to reduce integration friction and automate workflows across quoting, ordering, and customer management. Executive Vice President Sanjib Sahoo described the MCP Server as a way to bring AI directly into the flow of business, giving partners a secure, real-time connection to Ingram Micro’s data mesh without building custom integrations. Trust X Alliance member Matrix Integration estimates the platform will save its team between 1,000 and 1,500 hours this year. IT Design Consulting CEO Ryan Evans said his team cut quoting processes from hours or days to seconds using the XI Hub integration. Ingram Micro is offering on-demand training sessions to help partners build AI-powered solutions through the platform. The company is positioning the offering as part of its broader strategy to make Xvantage an intelligent operating layer for the global channel. Canadian partners should watch how quickly small MSPs adopt the plug-and-play connectivity, since Ingram Micro reports that smaller providers are the fastest adopters so far. D&H Distributing is now authorized to carry Dell Technologies’ full enterprise storage portfolio in the United States and Canada, adding a new sourcing option for partners after Dell ended its distribution relationship with Arrow Enterprise Computing Solutions last month. The Harrisburg, Pa.-based distributor is bringing Dell’s advanced infrastructure, including Dell Apex as-a-service and subscription technologies, to its Advanced Solutions+ business unit. Chief Commercial and Consumer Officer Marty Bauerlein told CRN that Dell’s decision followed an RFP process and was influenced by D&H’s execution capabilities and growth mindset. Partners including Precision Computer Services and CompuCom have praised D&H’s responsiveness and collaborative approach. D&H says its Advanced Solutions+ unit now accounts for more than 25 percent of its overall business. For Canadian partners, the move adds another distributor option for Dell storage and server infrastructure at a time when Dell is also rolling out program changes focused on AI outcomes and faster rewards. The timing means partners can evaluate sourcing alongside the new rebate and registration structures Dell is expected to introduce this month. In Brief – Acronis unveils autonomous IT platform update with AI-driven console, service desk, and migration tools for MSPs. NCC Group partners with SailPoint to strengthen identity security services for human and non-human identities. Lexful announces general availability of its AI-native IT documentation platform for MSPs, with plans to join the Pax8 and Sherweb marketplaces before the end of 2026. Circana research presented at XChange August says AI’s workforce shock is unlikely to ease in the near term. Full details and links in the show notes or the blog post. Later today on In The Channel, my conversation with Exabeam about rebuilding the MSSP commercial model to fix the economics of managed SIEM. And if you haven‘t heard it yet, check out my conversation with Chris Fabes from TD SYNNEX Canada about his three-sided view of the channel. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Craig Patterson, global channel chief at Exabeam For years, SIEM has been one of those technologies that looked good in theory but was genuinely hard to build a profitable managed service around. Deal-by-deal discount negotiations, licensing structures built for enterprise resale rather than recurring managed services revenue, and no predictable floor on margin. For many MSPs, the math just never worked. Exabeam – the combined company formed from the merger of the original Exabeam and LogRhythm – is making a direct play to change that. Global channel chief Craig Patterson and senior director of service provider alliances Peter Stratis join In The Channel to walk through the new MSSP commercial framework inside the recently launched APEX Partner Program. Two new licensing pathways: a single-pool capacity model for high-volume, multi-tenant environments serving SMB and mid-market clients, and a federated subscription model that isolates customer environments for compliance and data sovereignty requirements. For Canadian MSSPs navigating PIPEDA, OSFI E-21, or Protected B, that second model is the one to pay close attention to. Peter Stratis, senior directof of server provider alliances at Exabeam The conversation also covers Sherpa, Exabeam’s new AI-powered partner enablement platform – a move away from the traditional LMS toward an always-on coaching tool that can join partner sales calls in real time – and Agent Behavior Analytics, Exabeam’s new capability for detecting malfunctioning, misaligned, and subverted AI agents inside customer environments, included at no additional cost. The standout line from Peter Stratis – who called this his first-ever podcast appearance – is the one worth writing down: “We treated our service providers like resellers, unfortunately.” The new framework is a direct acknowledgment of that history, and an attempt to rebuild the commercial relationship from the ground up. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. If you’ve been in the channel for any length of time, you know that SIEM has always been one of those technologies that seems great in theory but has been genuinely hard to build a profitable managed service around. Licensing models that weren’t built for multi-tenancy, unpredictable costs, discount structures that made margin planning more of a guessing game than a business model. A lot of MSPs have looked at the security operations space and quietly backed away for exactly those reasons. Exabeam, the combined company that emerged out of the merger of Exabeam and LogRhythm, is making a direct play to change that. They have overhauled their channel program into what they’re calling the APEX Partner Program and at the centre of it is a new commercial framework built specifically for managed security service providers. Two distinct pathways: one for high-volume multi-tenant environments and one built with compliance and data sovereignty in mind. For Canadian MSPs navigating PIPEDA, OSFI E-21 and Protected B requirements, that second lane is worth paying close attention to. I’ve got two Exabeam executives here to walk us through it. Craig Patterson is Exabeam’s global channel chief and Peter Stratis is the senior director of service provider alliances, the person who’s been working directly with MSSPs to build this out from the ground up. Let’s get right into it. My chat with Craig Patterson and Peter Stratis. Gentlemen, thank you for taking the time. Craig Patterson: Thank you, Robert. Super excited to be on here with you today, my friend. Peter Stratis: Thank you. Robert Dutt: Craig, can you just kick us off with a quick version of where Exabeam sits right now? You know, you guys went through a significant merger with LogRhythm not that long ago. Now you’re pushing an updated partner program. For solution providers who maybe haven’t been following closely, what does the combined company look like from a channel perspective? Craig Patterson: The short answer, my friend, is that we’re sitting in an amazing place. We’re absolutely in a good place positioning to really drive value to our partner community. And so to give you a little more context around that, like you asked, we’ve spent the last 12 months really kind of rethinking, reimagining the whole partner ecosystem in a way to create value for all of our partners globally. And so there was a number of things we went through over the last 12 months. We spent a lot of time really going to this assessment loop, understanding everybody’s perspective. So we did that by having very strategic conversations with our top-tier partners. We did some survey work. We looked at the broad landscape in terms of the trends that the partners are really looking for in these modern channel programs. So all of that really became this assessment loop. The output of that is that really became the foundation for what we built here with APEX. And so with APEX, the Exabeam APEX Partner Program, what you have here is you have a program that’s really centered on value that’s really focused on solving a problem that exists in our market today around enablement. And so when you think about enablement today, I’ve written a lot of articles on this. Most enablement programs really don’t drive to the level of outcome that companies are looking to have. Outcomes like conversion rates, outcomes like time to first deal, outcome rates like retention rates, all these things. And so what we’ve done is we’ve really focused on enablement as the key catalyst to really drive value to our partners. And so with that, we’ve launched new enablement programs really with a focus on increasing their competency level so we can align to those outcomes we’re looking to have with our company’s operating plan. And so there’s a lot of thought that’s got into this. The short answer is we have a program that’s built on value. It aligns to where the market is going and what partners are really asking for. Robert Dutt: Peter, your title as senior director of service provider alliances is a pretty specific role. Can you tell us a little bit about what that looks like sort of on a day-to-day basis and the big problems that you’re focused on? Peter Stratis: Sure thing. Thanks, Robert. Well, I’ve been with Exabeam for about eight years now and service providers have always been a key component of not only our channel strategy, but our go-to-market and just from our net new revenue perspective. After our merger with LogRhythm, that actually continues and if anything, it’s only been more emphasized because both from an on-prem and from a cloud perspective, we see the MSSPs being a strong driver of that strategy of our go-to-market. So over the last eight years, we’ve seen that trend of not only on net new revenue, net new logos being a major part of our business, but then how do, to Craig’s point, how do we support them? To be quite honest, in the past, it was quite difficult. We really didn’t have any kind of structured pricing for these partners. It was, to say the least, it was more of a resale program that had some discounts tied to it. So through Craig’s efforts, through our whole surveys and our intent to really go after this market and treat them the way they should be treated, he mentioned that we did these surveys. We asked internally, what do you look for in a service provider partner? We asked externally what these partners were looking for from us. And that’s when in building the APEX Partner Program here at Exabeam, we also took into account what service providers would look for in a new partner program. So that’s everything from pricing to support. Craig mentioned enablement. Enablement is a huge part of that, where they felt in the past they were just lumped up as just a regular partner. Now we have supported APIs, documented APIs that most, if not all, of our partners are using as part of their foundation for their services. So we’ve really come a long way and continue actually to build upon that, as you’ll see throughout 2026 and beyond. Robert Dutt: Okay, let’s get into the framework itself. You guys positioned it at launch as solving commercial and operational friction for MSSPs. Curious, what did you hear that friction looked like in practice? What were MSSPs telling you was broken or was a big challenge? Craig Patterson: Yeah, so I’ll take a stab at this and I’ll let Peter give more context. So a lot of this came out during that assessment phase. Robert, we’re talking to the MSSPs globally. I’m like, what’s working? What’s not working? What would they like to see incorporated into the MSSP program 2.0? So a lot of the feedback we heard was really around the flexibility. Being able to have a license that is catering to all the customer demand they have beneath. So it’s really giving them the flexibility to buy that one license and carve it up as they see fit. And giving them more flexibility on the commercial terms. That was a lot of the commentary we heard. The other thing we heard was really they wanted more value as it leads to the enablement side. So obviously getting them enabled on the pre-sales side, but more importantly on the post-sales side. So they could actually drive those implementations, drive the management and really help those customers create a lot of value. And so I think those were kind of the big levers that I heard from those assessments. And then in practice, Peter can give you some more context in terms of how we’re putting all this together. Peter Stratis: Yeah, thanks Craig. A lot of what we heard from the service provider community in the past was friction. So when they’re trying to price out their services and our product and etc., they were seeing friction at onboarding. They were seeing friction in trying to predict their margin on deals. As mentioned, not airing any dirty laundry here. It was more like a resale program. So we gave discounts and there were very opportunistic discounts on a deal-by-deal basis. So they didn’t build predictable service models around it in the past. And then you always hear the buzzword, multi-tenancy. We kept on getting asked about our multi-tenant roadmaps, etc. We’re looking at this framework as a way of solving for that. We continue to make feature enhancements into the platform that will strive for that multi-tenancy. But the way we’re solving for it is by these two pathways. One is that single license, pooled capacity, data segregation model. And the other is that federated workflow that we announced where it’s more for, whether you’re within data sovereignty, if in different regions or just different use cases from a compliance perspective, whether it’s healthcare or finance, and you have to keep these environments isolated. We have a plan and we worked with our MSSPs specifically to have these kind of pathways. So we heard from our MSSPs and we actually developed these two pathways with them in mind. So they were in the design phase and in the rollout phase for both federated and the single pool capacity. Robert Dutt: The federated model is such an interesting one, I think, for the Canadian market, specifically data sovereignty, huge topic. And there are specific compliance requirements, PIPEDA, OSFI E-21, Protected B status. It means that a lot of Canadian MSSPs can’t just kind of throw everything into one pool. Was that the sort of thing that was explicitly on the radar when you built this out or a happy coincidence of the architecture and the feedback that you heard along the way? Peter Stratis: It’s actually a little of both, right? So it just so happened to be the maturity of our platform. Even from our Exabeam New Scale platform, we went from an on-prem hardware appliance way back in 2012, to our version 1.0 was a SaaS product, to our native cloud. It was always a single-tenant solution. So it worked well for certain service providers that had the capacity. They had their APIs and their own platforms that could manage this solution. As you heard more and more about multi-tenancy and the need for data sovereignty and all that, we still had a big part of our MSSPs were asking for this single license pooled capacity. So we structured it in a way where for midsize organizations or even some small, medium business, you still have that single pool capacity using data segregation. You lose some of the customization, but you could actually solve for a lot of those customers in that model. And then you have another plan with the federated. So the more mature MSSPs are running both models in some capacity. They could still run that single license for their SMB play. And then for either large enterprise or very compliance-driven customers that want those isolated environments, they have that flexibility. And that’s what we built a framework around. Obviously, that’s one point of feedback that sort of directly informed the framework. Robert Dutt: You guys have said that this whole thing was built, as you said, with direct collaboration with your MSSP partners rather than kind of coming down on high. I’m curious along with what you’ve touched on already, what actually changed as a result of going through that process? What did you go in thinking you’d build and how did it come out differently because of what partners told you along the way to building it? Craig Patterson: Yeah. So I think there’s a lot of things that have been addressed. Obviously, the packaging and the commercial aspects as Peter was describing, but think about some of the fundamental problems in terms of partners want this path to profitability, right? Really understanding how they can create margin. That was one thing. Another path is like, how do I become enabled with Exabeam? And how do I stay informed in terms of where you’re going? Another problem we wanted to solve. So I think it’s a lot around the financial aspects of doing business with us. A lot of it’s around becoming enabled, becoming more knowledgeable on all the new features and releases that we’re dropping. And so those were some of the big fundamentals that we wanted to solve in the APEX framework. And then beneath that, obviously, is the whole MSSP play. And that’s what Peter’s been talking about. So you can probably give a little more context on that. Peter Stratis: Yeah. As mentioned, there is no one-size-fits-all. So the feedback we were getting was obviously their security platform was important to them. Some of them had an in-house platform they built on their own. And there’s ways of differentiating. So basic SIEMs are just going after alert monitoring. So how can I differentiate my service if I’m a service provider? Well, there’s ways of going to market, but also there were things we needed to do in the back office from a platform perspective to make those possible. So making our behavioral analytics available in these models so they can actually differentiate their services. As I said, we have a history of actually adding features quarter-over-quarter, month-over-month. So that’s not stopping. We didn’t announce necessarily multi-tenancy to the world. We announced a commercial framework for that. So you’ll continue to see on a month-to-month, quarter-over-quarter basis, features added to support not only the commercial framework, but the underlying platform to make it easier for service providers to add that operational efficiency, to add those differentiators from a product portfolio as well. Robert Dutt: Let’s talk about the economics underneath there. You use the term predictable margins as a phrase that shows up in the messaging. SIEM has historically been a tough service to make money on. Licensing models that didn’t fit the managed services motion, unpredictable costs on data ingestion, those sorts of things. What specifically changes for an MSSP’s P&L under the framework? Craig Patterson: Yeah. So I think there’s really two components here. The first is the whole financial package associated to the MSSP partners. And the second is the discounting framework. And so let’s maybe start with the discounting framework. One of the observations that we made during this whole assessment phase was the vast majority, Robert, of all of our deals were flowing through this non-standard process, which means the discounts that were aligned to the traditional framework were not putting the MSSP partners in a position to actually transact. And so what we did is we went through and we re-looked at the discounting framework and sort of realigned it based upon our actual data points. We looked at the last 12, 24 months, the discounts that were being derived to actually transact. And we sort of rebuilt the entire discounting framework for our company in a way that really empowers the MSSP partners now to have enough discount to actually transact without going to this non-standard queue. So what does it mean? Well, we really kind of flipped the script. Instead of 80% being non-standard, we believe 80% will flow through the standard process now because we’ve built the discounts in a way to align with what the market is looking for. That’s kind of the key component number one. And then as it relates to the discounting side, we reimagined how those discounts are calculated. And so now you kind of have your standard program discount. So that’s based upon your tier. So top-tier MSSP partners get the highest level discount. The second is deal registration. Obviously, they put the deal reg in that ties to a discount. Those are both standard common things. But what’s new, which is what you care about. What is new? Well, we’ve aligned the third discount based to their competency level. And so we measure that based upon certifications. And so if you think back to those choose-your-own-adventure books as a kid, we’re really giving the partners their own choose-your-own-adventure. And if they want to drive to the highest level discount, well, simply, MSSP partners got to go take all of our certifications, pre-sales and post-sales, so they have the highest level of competency to drive our services in the market. And our thesis around that is partners that have higher certifications, they’re going to be more active, they’re going to be more interested, they’re going to drive more pipeline. And if we do this the right way, Robert, they’re actually going to convert at a higher percentage, we’re going to see shortened sales cycles, all of which align to the operating plan of our company. So it’s kind of those two fundamental things that were addressed through that process. And then I’m sure Peter can fill in the detail for you. Peter Stratis: Yeah, if I can actually elaborate on that. Thanks for that, Craig. And just some historical context, Robert, as mentioned in the past, we treated our service providers like resellers, unfortunately, so it was very deal-specific in terms of what they were getting on a deal-by-deal basis from a discount. So the economics of it was they really couldn’t rationalize their margin predictability on an overall services basis. And you know, different regions go to market different ways. In Europe, Asia, Latin America, predominantly, it’s all SIEM as a service and MSSP owns the license. In the Americas, both US and Canada, we saw a lot of proliferation in the past of customer-owned licenses. So the MSSP would resell the license, and consequently, just provide managed services wrap on top of that. Not only do we see more of that MSSP-owned model now where it’s SIEM as a service in the US and Canada. So it’s proliferated itself throughout all the regions. Now with these frameworks, we actually are able to build these economics, the margin predictability, as Craig mentioned, because now they know as a standard, what they’re going to be selling for. So especially as we do this federated model, and even the single license, you know what your price is across the board, you know what license you’re buying, you know what price you’re buying it for, you know, the more customers you add to these models, the more your profitability will increase as well. So it continues to grow from a pure profit play. Partners want to know what their margin would be as their customer licenses grow. And this is exactly what the framework did. Robert Dutt: This is sort of a broader question around MSP/MSSP distinctions as opposed to directly about the framework. But there’s a distinction worth drawing between an MSP trying to bolt a security practice onto the existing managed services business and the established MSSP who’s been at this for a year or who has built it up. Are those two different conversations for you? And if so, what are the different entry points and care-abouts? Peter Stratis: So it’s interesting, not only because of this announcement, even prior to it, the announcement of the APEX Partner Program here at Exabeam caused a lot of interest from partners and different kinds of partners. The traditional MSP, when inquiring, it was kind of hard when we were vetting them that they had no security practice of their own. So oftentimes they would actually outsource that security to an MSSP, to a classic MSSP, or maybe just resell services from those other organizations. We see that, we see a lot of interest from MSPs with that. And we see VARs or resellers come to us that want to build managed service practices as well. So we look at both of these in two different ways. One, how can we take care of these partner inquiries now, and then how can we grow with these organizations? So both MSPs and resellers that are interested in managed services now, our first inkling is to try to introduce them to our current managed service base. These people have the experience, they have the certifications, they have the technical knowledge. We’ve seen that move from a lot of MSP partners actually having channels of their own. So they actually sell their MDR or MSSP services through a channel of resellers or MSPs. But then if that’s our first step with these type of partnerships, then it’s like, how can we grow within your organization? How can we help you get the technical skills required? Because for a true MSP to have success, not only in SIEM, but just security as a service, you can’t just train one or two people, you need the 24-by-7 support, you need the tier one and tier two level of support services as well. So you have to grow your organization or outsource it to people that are already prepared to handle that. So that MSP play, we actually see it more and more going towards our current managed security service providers and getting that as a resource. Craig Patterson: Just to add a little more context to that too. So this actually becomes a very interesting point for the distributors worldwide as well. Because a lot of what they provide in terms of value is helping those MSPs in terms of deployment and management of the services. And so we’ve gone through the vetting process globally, looking at all of our distributors and we’ve handpicked our strategic distributors around the world. So if we have MSPs that want to come into the program, but they’re not ready on that post-sale side, well, guess what? That can become the role of the distributor. And secondarily, this is where the enablement really comes into play as well. And so that’s why we’ve built very specific paths on enablement, pre-sales and post-sales, where partners can choose their own adventure. “Hey, if I want to get going on the pre-sale side, well, guess what? I can simply resell.” Or, “Hey, I want to really start focusing on the post-sales services implementation.” I can start to take the enablement around those courses to become more of an expert to really give me those new capabilities. And so there’s a whole conversation around what we’re doing on enablement with our brand new Sherpa that’s really given a lot of these partners those capabilities. Robert Dutt: On the note of Sherpa, an AI-powered tool for partners, it’s essentially a virtual channel account manager in terms of enablement, onboarding, that sort of thing, especially for an MSSP who’s new to SIEM. How does it change the friction of getting started with Exabeam as their platform? Craig Patterson: You’re going to love this. You’re going to love this. So we’ve sort of reimagined all of the enablement. Again, when you look at traditional enablement, it’s like most enablement is built in these LMS platforms. Like, “Hey, partner, go log on to this LMS platform, get your certification, and then we expect you to actually know what the hell you’re doing.” Reality is that’s not what happens. They log on to the LMS platforms. They fast-forward as quickly as they can to the end. They turn the volume down. And then when the quiz comes, they use AI to answer the questions. And so they just find a way to get the certification. The reality is none of that helps them be better in life or actually raise their competency. And so that’s a problem we took on head-on with Sherpa. And so Sherpa was built in a way to really change the way partners learn with the whole goal of raising their competency level so they can be better on the market. And there was really like three use cases we were trying to solve with the emergence of Sherpa. The first is like you think about this global ecosystem that Peter and I have. We have 3000 partners. The partner ecosystem looks different. We have VARs. We have MSPs. We have MSSPs. We have distributors. We have the trusted advisor market as well. All of them have different needs in terms of where they are from a learning perspective. And so the first use case, Robert, is simply like a tool to be able to ask questions. What are the use cases? How do I position this? Why is SIEM or UEBA better than the competition? Just an always-on tool for partners to ask questions. And so that was kind of use case one. And then the cool thing around that is you think about the ecosystem being very global in nature. The other problem with LMS platforms is I’ve got partners in Japan. Well, that means the LMS platform they log on to needs to be able to talk to them in Japanese. And so the beauty with Sherpa, it does all the translation for us. And we’ve got 15 plus languages that are now live in Sherpa. Partners in Japan are talking to it. We got partners in India and all over the world really asking questions in terms of how we position our services. And that integration can be done by just logging on to our portal. You’ll see a bot pop up. They can just simply ask a question. It integrates in Teams, integrates in Slack. So that was use case number one. Use case number two was we reimagined the whole enablement certification platform. And so it’s a very dynamic learning experience. And so the way it happens is you log on, there’s a topic that you like, you click on that, you start learning, it asks you questions, it asks you to position services, and then you record your answer to how you’re actually positioning those services or the features. And it gives you feedback like, “Robert, you did really good on this aspect, but next time you should use this and this.” Or, “Robert, if you’re talking to a customer that’s in this vertical, you should talk about this use case because that’ll help resonate.” And so the whole certification process has been rebuilt and that’s the second use case. The third use case, this is a game changer. And this really goes to your question. And it’s an always-on coach. And so partners are now able to invite Sherpa to calls. And so as they’re having those conversations with customers, and the customer may say something or give them an objection, well, in the background, Sherpa will give them the answer to that objection and say, “Customer said this, talk to them about this.” Or, “Have you shared this new feature that was just released in the quarterly launch?” So it’s like this always-on coach, always-on assistant to really give them what they need. And then we’re putting it on this innovation roadmap. And so every single quarter, we’re launching new innovation in Sherpa. As an example, we’re now launching our LinkedIn integration. So if you’re an MSSP partner, you log on to Sherpa, you’re connected to LinkedIn, it’s going to ask you, if Sherpa can look through your network to find customers that may be a good fit for our services. And then it’ll say, “Okay, great. We found these contacts. Should we go ahead and write the campaign? Should we write a campaign that you can use to send to those customers in your ecosystem on LinkedIn?” And so quite honestly, I think we’re bleeding edge in terms of really being able to use AI and adopt AI in a way to drive good outcomes, well beyond where most companies are with their simple ChatGPT things like that. We’re actually driving outcomes. Robert Dutt: The rise of AI baked into the partner program and partner tools is a fascinating space for me to watch. And that certainly, you make a compelling case for the role of Sherpa there. That sounds really interesting. A quick one on the product side, not directly related here, but just out of curiosity, Exabeam just dropped Agent Behavior Analytics in your April release, sort of extending behavioral detection to AI agents, ChatGPT usage, Copilot activity, those kinds of things. For an MSSP looking to take this to market as a service, is it a new revenue line? Is it an upsell? Or is this sort of becoming table stakes that clients expect to see bundled into what you’re doing for them? Craig Patterson: I’m glad you asked. It was just recently at RSA, the conference, obviously AI is the buzzword, but what do you do with that? When we presented the agentic behavior analytics to a lot of our partners or potential new customers, the question that was often asked was, “Well, how much is this extra?” And that’s not how we license our product. So the behavior analytics has been part of our solution since our inception from our analytics model. So specific to AI, this is going to be, you could differentiate your service from other service providers by using this behavior analytics, but by no means is it an extra cost on the MSSP’s behalf. So they’re going into an organization that has a thousand users, human entities, and overnight they now have 10,000 non-human entities. We look at and model all of them using our analytics. So now you actually have at least a basis of what’s normal from a behavior standpoint for both non-human and human entities. So we really change the game, but haven’t changed the pricing along with it. So it comes naturally within our platform. So no change for me as a partner, but if I can find a way to upsell based on it, all the better. If not, I add additional features. Hopefully my customer is more happy. Peter Stratis: I was just going to say, if you look at the macro trends we’re seeing, this is the number one conversation that’s being had right now, especially like you look at the financial sector. Every single company is facing this problem. And so this really, not only does it give them a new use case to go after, I think it just makes the overall security services of Exabeam more relevant based upon what’s happening in the overall market, which all that makes the revenue stickier, makes those conversations more impactful that those MSSP partners are having. Craig Patterson: Yeah. Well, what I’m going to mention is operational efficiency and service differentiation is what’s key to our MSSPs and their success. So the license is foundational. And now that we’ve actually solved for being predictable from a margin perspective, how can they differentiate themselves, making them operationally efficient using automation, using our threat detection, and then also the service differentiation. And the other thing too, just thinking through this a little bit, I mean, there’s different AI agents that exist out there that are doing different things. You think about the malfunctioning agent, the one that’s just off base and it’s doing things that are just incorrect based upon the fundamentals or foundation of the AI agent. That’s one thing that gets addressed by looking at the abnormal behavior. The second is the misaligned agent, the ones that are pursuing goals in a way that could negatively impact the company. And that gets a little bit more scary. But really what gets scary is those subverted agents, the ones that have been hijacked that are actually causing harm. And so you think about all those different use cases that are happening, and that’s the beauty of what we just released is our new ABA, sort of creating this new category in the market. That’s really what our ABA is looking for, is all those different things that are happening, whether it’s misused, misaligned, or subverted. All that can be detected through this new agent behavior. Robert Dutt: Okay, last question for me. If I’m an MSP who’s been sitting on the sidelines, I’ve been thinking about them or are upgrading my security operations practice. What’s one thing that you wish I understood about the opportunity and the economics, but I probably don’t at this point? Peter Stratis: It’s all about how they actually start off. They’re interested in selling managed security, but they don’t know that they have to standardize their delivery model. They can’t make it where every customer is custom, because that’s when that price predictability goes away. So everything from onboarding to customizing your offering has to go away. You might be able to do it for a certain amount of customers, but you have to build a model that’s repeatable. Automation is going to be very important to that. And then finally, you could add optional add-ons, but you have to resist the temptation to over-customize everything. The great thing about what Craig has done with the APEX Partner Program and the way we built it out here at Exabeam is it supports all of this through all the enablement efforts. So Craig mentioned all the enablement built into the program, but then we have certification tracks. So we’ll help you along in that process. And we have everything from APIs and the use case and the scripts to help you automate that track for you to make it easier, but just don’t jump in and try to do a custom solution for each customer. Robert Dutt: Gentlemen, I thank you very much for your time. Once again, I appreciate your walking us through the commercial framework. Craig Patterson: Thank you, Robert. Appreciate it. Peter Stratis: Thank you, Robert. Robert Dutt: There you have it. Craig Patterson and Peter Stratis from Exabeam. I’d like to thank Craig and Peter for their time today. And a special note, this was Peter’s first podcast appearance. You never would have known it. A few things I’ll leave you with. First, if Peter’s candid admission landed for you — that Exabeam used to treat service providers like resellers with opportunistic deal-by-deal discounts that made it impossible to build a predictable margin — sit with that for a moment. Not unique to Exabeam. That was the industry. And it goes a long way to explaining why so many MSPs have struggled to make managed SIEM work as a business. The new framework is a direct attempt to fix that math. Two pathways: a single-pool capacity model that works well for SMB and mid-market clients, and a federated model that isolates environments for compliance-heavy customers. The discounting structure has been rebuilt from the data up with the goal of moving 80% of deals through a standard process. Up from what Craig described as the opposite of that. The Sherpa AI tool is worth watching closely, not just as a training platform replacement, but as an always-on coach that can actually sit in on partner sales calls and surface real-time objection handling. The LinkedIn integration is coming next, and it starts looking less like an LMS and more like a business development tool. And the closing advice I’ll leave you with is Peter’s. If you’re an MSP thinking about entering the security space, standardize your delivery model before you take on your first customer. Resist the urge to customize every environment. That’s exactly where price predictability and profitability goes away. Thanks as always for listening. In The Channel is available on Apple Podcasts, Spotify, YouTube, and all the major podcast directories. If you’re finding value in the show, leave a rating or review. It goes a long way to helping other folks in the channel find us. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
Most vendors at Black Hat USA 2026 have something to say about agentic AI. Jeremy Powell, CISO at Sumo Logic, spends this conversation on the harder proof, which is what happens when a company runs its own product in production at scale. Sumo Logic has been doing that for roughly ten to eleven months. Powell calls it customer zero, and it shapes how he answers almost every question here. The Sumo Logic SecOps team ingests seven exabytes a day globally, which Powell puts at roughly half a billion 8K movies. Against that volume, the team reports 100 percent first level triage handled through automation and about 25 hours saved per analyst per week. Everything learned in production feeds back into the product organization in real time. Security tooling is notoriously hard to use, especially in the enterprise, and Powell is candid that the realization drove a concerted engineering and product effort to fix it. One result showed up at Black Hat this week in the evolved version of Mobot, the conversational interface inside the product. Users can now prompt their way into an investigation, see the audit trail behind it, and get to an answer without configuring their way there first. So how do you trust a decision an agent made? Powell points to an audit trail and a log trail behind every decision the SOC Analyst Agent produces, traceable back through every conceivable log to the root decision. He describes it as human on the loop rather than in the loop. People keep the decisions. Execution and delivery get automated. That changes the shape of the job. Powell describes the SOC becoming something closer to an agile QA organization, where analysts assess the fidelity of what the agent did instead of grinding through first level alerts. On the question of whether automation costs analysts their jobs, he uses a phrase he borrowed from someone else: pay attention to the tension. His answer is that the work gets better and more interesting and the analysts get more capable. The same logic carries up to the board. Powell argues a security leader's job at the executive level is to measure risk transparently and report it accurately, and that boards will build a trend line out of three data points. Telemetry becomes the raw material for informed risk decisions communicated in an executive-friendly way, with the full reasoning available on request. As he puts it, the auditor cares, and the board cares if you fail the audit. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Jeremy Powell, CISO, Sumo Logic LinkedIn: https://www.linkedin.com/in/executivembajeremypowell/ RESOURCES Sumo Logic: https://www.sumologic.com/ Sumo Logic at Black Hat USA: https://www.sumologic.com/events/black-hat Dojo AI agentic security and cloud operations: https://www.sumologic.com/blog/dojo-ai-agentic-security-cloud-operations Building an AI-first SOC, the customer zero story: https://www.sumologic.com/blog/building-ai-first-soc-customer-zero See Mobot in action: https://youtu.be/ZZLXaft7tYM View all of our Black Hat USA 2026 coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Jeremy Powell, Sumo Logic, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, Black Hat USA 2026, agentic AI, SOC analyst agent, security operations center, human on the loop, first level triage, security automation, telemetry, exabyte scale, customer zero, Mobot, conversational interface, CISO, board reporting, risk communication, SIEM, AI governance Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
In this episode of Shift AI, Shay Sandler, CEO and co-founder of Vega, joins host Boaz Ashkenazy for a wide-ranging conversation on why the legacy SIEM is breaking down just as security teams need their data the most.Shay grew up in Israel studying math and physics in a famously competitive class of gifted kids, then spent six years in one of the country's most elite military intelligence units before joining Granulate, a cloud cost optimization company, as one of its first ten employees. Granulate was acquired by Intel for $650 million, and after a year inside Intel, Shay left with his former Granulate colleague Ellie to found Vega — a decision he says was pushed forward by a month of reserve duty after October 7th that reminded him how much he missed solving hard problems with his old team.The two dig into why traditional SIEMs, built for a pre-cloud world of centralized data, are collapsing under multi-cloud, multi-region, siloed telemetry — and why teams that once filtered data down to save on SIEM costs now need all of it to keep up with threat actors wielding frontier models. Shay walks through Vega's architecture: querying data in place in commodity storage like S3, federating across regions and clouds without duplication or egress costs, and a deterministic, auditable natural-language-to-KQL layer that lets AI agents run threat hunts a human could fully verify.This episode is for CISOs, security operations leaders, detection engineers, and startup founders building in cybersecurity who want to understand how AI-native architecture, not just AI features, is reshaping enterprise security.Chapters[00:00] Introduction: Shay Sandler's path to founding and leading Vega[02:07] Growing up gifted in math and physics, and finding cybersecurity[04:18] Six years in an elite Israeli intelligence unit, and the "everything is solvable" mindset[06:08] First paid job at 14: distributing meat before dawn in southern Israel[08:37] Granulate, the $650 million Intel acquisition, and missing the startup thrill[10:43] October 7th reserve duty and the spark to build Vega with co-founder Ellie[15:04] How legacy SIEM broke under multi-cloud, siloed security data[17:32] The post-Mythos era: frontier models as tools for threat actors[23:16] Vega's three primitives: commodity storage, federation, and an AI-native interface[27:50] Natural language to KQL as a transparent, auditable layer for AI agents[30:05] AI as a "scalable engineering capability" for lean security teams[36:40] Velocity as the new core metric, and the closing thought: creativity and engineeringConnect with Shay SandlerLinkedIn: https://www.linkedin.com/in/shay-sandler-305508107/Connect with Boaz AshkenazyLinkedIn: https://www.linkedin.com/in/boazashkenazy/Email: boaz@shiftai.fm
KI-Labels, Musikklau und Milliarden für Rechenzentren – was passiert gerade? In dieser Folge von „Ich glaube, es hackt!“ geht es einmal quer durch die spannendsten Entwicklungen der KI-Welt. Los geht es mit einem Nachtrag zur Diskussion um Open-Weights-Modelle und der Frage, warum ausgerechnet ein chinesisches KI-Modell bei der Abwehr eines Cyberangriffs erfolgreicher war als amerikanische Modelle mit strengen Guardrails. Anschließend werfen wir einen Blick auf die neuen EU-Regeln zur Kennzeichnung KI-generierter Inhalte. Was bedeuten die neuen AI-Labels? Wann muss ein Bild oder Video gekennzeichnet werden? Und wo liegen die Grauzonen zwischen Bildbearbeitung und echter KI-Manipulation? Danach wird es juristisch: Die GEMA hat gegen den Musikgenerator Suno einen wichtigen Erfolg erzielt. Wir diskutieren, warum das Urteil für die gesamte KI-Branche weitreichende Folgen haben könnte und weshalb die Berechnung eines möglichen Schadensersatzes alles andere als einfach werden dürfte. Außerdem sprechen wir über die gigantischen Investitionen in KI-Infrastruktur. OpenAI sucht Finanzierungen in Milliardenhöhe für neue Rechenzentren – und ausgerechnet Nvidia hilft dabei mit. Entsteht hier die nächste große Technologieblase oder erleben wir lediglich den nächsten Schritt der Digitalisierung? Zum Abschluss gibt es wie gewohnt jede Menge Technik-Kuriositäten: Warum manche Mobilfunknetze Telefongespräche nach zwei Stunden automatisch beenden, wie sich Dateien per QR-Code übertragen lassen, warum München endlich die Papierunterschrift abschafft und welche kleinen Tools den Alltag auf dem Mac deutlich angenehmer machen. Themen dieser Episode Open-Weights vs. Closed-Source-KI KI bei der Cyberabwehr Neue EU-Kennzeichnungspflicht für KI-Inhalte Deepfakes und AI-Labels GEMA gegen Suno AI Urheberrecht und KI-Training OpenAI sucht Milliarden für Rechenzentren Nvidia finanziert KI-Infrastruktur Smartphone-Telefonate mit Zeitlimit Datenübertragung per QR-Code Digitalisierung der Verwaltung Praktische Mac-Tipps -- Links zur Folge immer auf https://podcast.ichglaubeeshackt.de/ Wenn Euch unser Podcast gefallen hat, freuen wir uns über eine Bewertung! Feedback wie z.B. Themenwünsche könnt Ihr uns über sämtliche Kanäle zukommen lassen: Email: podcast@ichglaubeeshackt.de Web: podcast.ichglaubeeshackt.de Instagram: http://instagram.com/igehpodcast
On Cybersecurity Today on the Weekend, host David speaks with Matt Burke, CISO of Bespoke Concierge MD, a telemedicine provider with doctors licensed in all 50 states, about defending patient data amid rising healthcare threats in 2026. Burke explains why healthcare is heavily targeted, recounts a formative 3 a.m. incident rebuilding a critical connection during surgery, and outlines his top concerns: increasingly sophisticated bad actors, "hacking as a service," and user mistakes. He emphasizes education, strong security tooling backed by a proactive/reactive SOC, and rigorous practice of incident and disaster recovery plans, balancing prevention with rapid response. The discussion also covers AI's benefits and risks, leadership support for security, the importance of MFA for both work and personal accounts, and Burke's wish for broader adoption of effective SIEM tools. 00:00 Weekend Show Intro 00:39 Meet Matt Burke 01:23 Concierge Care Model 02:45 Why Healthcare Security 03:13 Origin Story 3AM Call 05:20 Top Threats 2026 06:29 Defense Tools That Work 07:50 AI Helps And Hurts 09:37 Winning Doctor Buy In 10:57 Castle Versus Response 13:42 Threat Surge And Resilience 18:17 Culture And MFA Everywhere 19:59 Career Advice And Magic Wand 22:33 Closing Thanks
The future of cybersecurity isn't just faster detection - it's AI that predicts, investigates, and responds before attackers succeed. In this masterclass episode, InfosecTrain breaks down how AI is revolutionizing Security Operations Centers (SOCs) through intelligent threat triage, automated investigations, and SIEM log analysis.The "course titled" SOC Analyst Training Program accelerates your career in modern AI-driven cyber defense.
SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
DShield SIEM Update https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156 Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivers https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875 Zoom Account Takeover Patch https://www.zoom.com/en/trust/security-bulletin/zsb-26014/ Forgotten UEFI shims undermining Secure Boot https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich
Can you build a fully functional, high-scale SIEM in just two weeks for under $7,000? In this episode of the Cloud Security Podcast, hosts Tim Peacock and Kyle Champlin sit down with long-time collaborator Dan Lucier, Founder of Nano, to unpack how he "vibe-coded" an entire SIEM from scratch during his end-of-year holiday break. Dan shares his journey of leveraging bleeding-edge AI code assistants to go from a Postgres prototype to a blazing-fast, production-ready SIEM built on Rust and ClickHouse. In this episode, we cover:
In this Tech Corner, George Tsilis breaks down how CrowdStrike (CRWD) is benefiting from rising demand for cloud security, AI-driven threat detection, and next-generation SIEM solutions, while highlighting the company's strong earnings and accelerating growth.George also examines the key risks for investors, including CrowdStrike's premium valuation, profitability concerns, and growing competition in cybersecurity.======== Schwab Network ========Empowering every investor and trader, every market day.Subscribe to the Market Minute newsletter - https://schwabnetwork.com/subscribeDownload the iOS app - https://apps.apple.com/us/app/schwab-network/id1460719185Download the Amazon Fire Tv App - https://www.amazon.com/TD-Ameritrade-Network/dp/B07KRD76C7Watch on Sling - https://watch.sling.com/1/asset/191928615bd8d47686f94682aefaa007/watchWatch on Vizio - https://www.vizio.com/en/watchfreeplus-exploreWatch on DistroTV - https://www.distro.tv/live/schwab-network/Follow us on X – https://twitter.com/schwabnetworkFollow us on Facebook – https://www.facebook.com/schwabnetworkFollow us on LinkedIn - https://www.linkedin.com/company/schwab-network/About Schwab Network - https://schwabnetwork.com/about
This episode covers a hacker's claim of stealing 35GB from Accenture—including source code, Azure personal access tokens, RSA keys, and SSH keys—while Accenture calls it an isolated, remediated matter, leaving uncertainty about potential downstream risk to its Fortune 500-heavy client base. It also highlights a deepfake image of Senator Mitch McConnell debunked after Google's invisible SynthID watermark identified it as AI-generated, noting watermarking depends on tool participation. The show warns of an undocumented Tenda router firmware backdoor using an alternate password ("RZadmin") with no patch available, and reports Ubiquiti fixes for seven critical UniFi OS vulnerabilities, including a max-severity command injection in UniFi Connect. Finally, it describes how Venture Employer Solutions used ML/LLMs to filter low-value logs before SIEM ingestion, cutting firewall log volume 83%, saving about $250K annually, and halving mean time to response. 00:00 Sponsor NordLayer 00:37 Headlines Intro 01:08 Accenture Breach Claim 04:25 Deepfake Watermark Win 05:47 Tenda Router Backdoor 07:22 UniFi Critical Fixes 09:10 AI Cuts Log Noise 11:09 Wrap Up And Thanks 11:41 Sponsor Message
All links and images can be found on CISO Series This week's episode is hosted by David Spark, producer of CISO Series and Nick Vigier, CISO, Oscar Health. Joining is our sponsored guest, Mitchem Boles, field CTO, Intezer. This episode was recorded live at Intezer's AI SOC event held at the NASDAQ in NYC. In this episode: Who owns the risk Before it gets better The SOC of zero The decision bottleneck A huge thanks to our sponsor, Intezer Intezer Forensic AI SOC is designed for enterprises managing high alert volumes across SIEM, EDR Network, identity, phishing, and cloud systems. These organizations often rely on MDRs to fill coverage gaps but face frustration with limited visibility, too many escalations, and missed incidents hiding in low-severity alerts. Learn more at Intezer.com.
Phishing-resistant MFA could have stopped a Chinese state-sponsored threat actor from spending over a year inside North American academic and medical research networks — and we're going to tell you exactly how it happened and what you need to do about it.A group called UNC5608, tracked by Google's Threat Intelligence Group (GTIG), exploited a vulnerability unique to REDCap — a research data platform that allows multiple software versions to run simultaneously. They got in via stolen admin credentials, planted custom malware called Infinite.red directly into REDCap's upgrade process, harvested credentials for over a year, then used those credentials to log into Google Workspace as a domain admin and create fake compliance rules to silently forward sensitive research emails — military strategy, geostrategic policy, advanced tech, specific pathogens — straight to Gmail accounts they controlled. And nobody noticed for a very long time.Prasanna and I break down the full attack chain, then walk through every prevention layer that could have stopped it: inventory management, patching, password hygiene, SSO, phishing-resistant MFA, passkeys, DBSC, context-aware access, compliance rule monitoring, credential separation across security domains, and logging. We also get into what backups can and can't do for you in a long-dwell-time attack like this — and why infrastructure-as-code and truly immutable golden images matter more than you might think.If you're running any kind of research platform, academic institution, or medical network — or honestly any organization that uses Google Workspace — this one's for you.Chapters:00:00 — Intro: The attack that phishing-resistant MFA could have stopped01:03 — Show intro & woodworking banter03:26 — What is a living-off-the-land attack?04:02 — Who is UNC5608 and who did they target?05:08 — How REDCap's multi-version design was exploited06:11 — Infinite.red malware and credential harvesting09:01 — Google Workspace infiltration via fake compliance rules10:18 — The keywords they were stealing: pathogens, military strategy, and more11:50 — What could the victims have done differently?12:42 — Inventory management, patching, and legacy version removal14:00 — Why you can't trust application-level authentication alone — use SSO15:18 — Phishing-resistant MFA and why it matters16:00 — Passkeys, FIDO, and why there are zero known attacks against them17:57 — Device-bound session credentials (DBSC) and context-aware access19:38 — Monitor your compliance rules — have a compliance rule for the compliance rule20:40 — Credential separation across security domains23:00 — Get some logging — XDR, SIEM, and catching exfiltration in progress24:00 — What can backups actually do in a long-dwell-time attack?27:00 — Infrastructure-as-code and the right cyber recovery approach28:58 — Protecting your golden images with immutable storage31:59 — Wrap-up
Het hilarische derde verhaal over Siem en Struis, over een Gouden Neus, een struisvogelwasserette en een groot misverstand. Voor alle fans van Juffrouw Pots! Uitgegeven door Van Goor Spreker: Tosca Menten
WBSRocks: Business Growth with ERP and Digital Transformation
Send us Fan MailThis week's enterprise software developments further demonstrate how rapidly vendors are embedding agentic AI, governed automation, and composable data architectures into core enterprise workflows. Rootstock Software strengthened its manufacturing and warehouse execution strategy through the acquisition of Ascent Solutions, while Anaplan expanded its AI planning portfolio with CoModeler, Custom Analyst, and Agent Studio to accelerate enterprise planning automation. In the go-to-market space, Apollo.io acquired Pocus to build a more agentic revenue operations stack, and Zapier partnered with Rillet to connect general ledger workflows with thousands of operational applications. Meanwhile, Databricks introduced Lakewatch as an open, agentic SIEM platform built on the lakehouse architecture, and Oracle launched Fusion Agentic Applications designed to place coordinated AI agents directly inside ERP workflows. Governance and enterprise trust also emerged as central themes, with Relyance AI unveiling Lyo to monitor how AI agents interact with enterprise data, while Salesforce introduced AI Foundry to operationalize research into enterprise-ready AI models. Finally, Spade raised significant funding to transform messy transaction strings into finance-grade AI data, reinforcing how semantic normalization and governed enterprise context are becoming foundational to the next generation of AI-native enterprise systems.In today's episode, we invited a panel of industry analysts for a live discussion on LinkedIn to analyze current enterprise software stories. We covered many grounds including the direction and roadmaps of each enterprise software vendors. Finally, we analyzed future trends and how they might shape the enterprise software industry.Video: https://www.youtube.com/watch?v=hekHpEgI0zMQuestions for Panelists?
At Infosecurity Europe 2026 in London, Bill Peterson, Senior Director of Product Marketing at Sumo Logic, joins us to unpack a tension every regulated security team knows well. When an incident hits, the business has to keep running. At the same time, regulators expect sensitive data to stay in region. For a long time, those two demands have pulled in opposite directions. Sumo Logic has spent 15 years as a SaaS platform on AWS, processing roughly four exabytes of data a day for around 2,000 customers. The core promise is speed, driving mean time to resolve as low as possible. Peterson frames it in business terms, because the person signing the check wants to know the return, not the bits and bytes. The news from the show is Sumo Logic availability on the AWS European Sovereign Cloud. EU organizations can keep their data in region, handled by EU staff, while still running the full platform for incident response. That turns a painful either/or into a checklist a regulated buyer can complete. Genesys is the first customer live in the sovereign cloud, with payment processor OpenPay preparing to follow. How does this play out for highly regulated industries? Sumo Logic is focused on finance, healthcare, telco, and government, the verticals feeling the most pressure. The path Peterson describes is simple: let Sumo Logic handle incident management, let AWS move and grow the data in region, and check the sovereignty box without giving up operational readiness. Underneath sits a full-featured SIEM and Dojo AI, the agentic approach Sumo Logic launched earlier this year. The goal is not to replace analysts but to keep a human in the loop while handing proven, repetitive work to an agent. Fix one server, confirm the solution, then let an agent patch the other 599 under oversight. A SOC Analyst Agent reaches general availability at Black Hat later this year, alongside an MCP server. On observability, the differentiator is reading both structured and unstructured data without normalizing it first. A zip code is structured; a cryptic web hook error is not. Sumo Logic reads both, which feeds directly into faster time to identify and faster time to resolve. For any leader weighing sovereignty against uptime, Bill Peterson makes a clear case that they can finally live in the same plan. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Bill Peterson, Senior Director of Product Marketing, Sumo Logic LinkedIn: https://www.linkedin.com/in/williampetersonjr/ RESOURCES Learn more about Sumo Logic: https://www.sumologic.com/ Sumo Logic on the AWS European Sovereign Cloud (announced at Infosecurity Europe 2026): https://www.sumologic.com/newsroom Infosecurity Europe 2026 event coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Bill Peterson, Sumo Logic, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, AWS European Sovereign Cloud, data sovereignty, incident response, mean time to resolve, SIEM, security operations, Dojo AI, agentic AI, SOC analyst agent, observability, log analytics, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Something has changed at the board level. Recorded in the media room at Infosecurity Europe 2026 in London, Ian Schenkel, VP Sales, EMEA & APAC of Intel 471, describes directors who no longer take security on faith. After a year of headline breaches from Jaguar Land Rover to Marks and Spencer and the Co-op, leadership wants proof rather than promises. What does the board actually want to know? A straight answer to one question: are we okay? Ian Schenkel starts with geopolitics. Nation-state activity, supply chain exposure, and shifting global markets all shape whether a business can keep running. Threat intelligence becomes the early warning system leaders use to decide where to move and which actors have a history of targeting their industry. The next question gets personal. Does this affect us? Have we already been hit? This is where Intel 471 leans on retroactive threat detection. When new indicators of compromise surface, an analyst can build detection queries in seconds against a SIEM, SOAR tool, SentinelOne, Microsoft, or Palo Alto, then report back to the board with a clear answer. How does intelligence reach the board without getting lost in the weeds? It travels as a story the board can act on. Intel 471 pulls its three core areas, cyber threat intelligence, attack surface management, and threat hunting, into a single report that scales from an executive summary to a detailed account of what was found and neutralized. The stories make it real. During merger rumors, an attacker registered a look-alike domain and emailed employees from it. In another case, Intel 471 warned an organization it did not yet work with about a politically motivated actor that was openly discussing it. The value is the early signal, long before perimeter and endpoint defenses ever engage. Sometimes the right move is not technical at all. It might be briefing executives on targeted ransomware or reminding employees to stay alert against the email that has not arrived yet. The throughline, as Ian Schenkel frames it, is prevention over reaction, and a board finally asking the right questions. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Ian Schenkel, VP Sales, EMEA & APAC, Intel 471 LinkedIn: https://www.linkedin.com/in/ianschenkel/ RESOURCES Learn more about Intel 471: https://www.intel471.com Connect with Ian Schenkel on LinkedIn: https://www.linkedin.com/in/ianschenkel/ Infosecurity Europe 2026 event coverage: https://www.itspmagazine.com/infosecurity-europe-2026-infosec-london-cybersecurity-event-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight ▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings KEYWORDS Ian Schenkel, Intel 471, Sean Martin, brand story, brand marketing, marketing podcast, brand spotlight, cyber threat intelligence, threat hunting, attack surface management, board reporting, geopolitical intelligence, early warning system, indicators of compromise, retroactive threat detection, business resilience, Infosecurity Europe 2026 Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Federal Tech Podcast: Listen and learn how successful companies get federal contracts
Finding a needle in a haystack would seem like a minor endeavor compared to what today's federal systems managers must face. Let's take a stab at a correct farmyard analogy – the haystacks double in size every day and are moving. That sounds like an exaggeration, but recent reports show that nine million zero-day exploits are released every day. AI is putting malicious actors on steroids. Chris Townsend, Global Vice President of Public Sector at Elastic, discussed the company's role in federal cybersecurity and data management. His argument is, essentially, that cybersecurity is a data problem. If threats are viewed from that perspective, the more data you can bring into your security environment, the more effective you are at defending it. Elastic enables security operations analysts who are responsible for detecting threats to keep up with today's tlandscape and cyber-attack velocity. Elastic's platform and tools can reduce false positives and help federal security operations centers (SOCs) prioritize valid threats. Townsend highlighted Elastic's agentic AI tools, which help SOC operators prioritize and remediate threats, reducing mean time to detect and respond. Elastic's partnership with CISA for a managed Security Information and Event Management (SIEM) as-a- service was also mentioned, emphasizing the importance of standardizing data for effective AI-driven cybersecurity. Townsend goes on to articulate Elastic's launch of a SIEM-as-a-Service offering for federal civilian agencies, featuring Elastic Security on Elastic Cloud. SIEMaaS delivers a cloud-based platform for next-generation, AI-powered threat analytics, incident response, and open-standards-based cybersecurity data ingestion. Here is a link to Chris' blog describing CISA's SIEMaaS offering and how it supports federal agencies' cybersecurity posture while reducing costs
WBSRocks: Business Growth with ERP and Digital Transformation
Send us Fan MailThis week's enterprise software announcements further confirm that the market is rapidly converging around agentic AI, semantic intelligence, and autonomous workflow orchestration. Blue Yonder introduced new AI agents and mobile applications aimed at strengthening supply chain execution and frontline operations, while Zendesk expanded its AI customer service strategy through the acquisition of Forethought. Actian launched an AI analyst designed to convert business glossaries into a live semantic layer, highlighting the growing importance of governed enterprise context for AI-native operations. Meanwhile, ActiveCampaign and Contentsquare announced new capabilities focused on customer engagement and digital experience intelligence. On the enterprise planning side, Anaplan expanded its AI planning portfolio with CoModeler, Custom Analyst, and Agent Studio, while Oracle continued embedding coordinated AI agents directly inside Fusion ERP workflows through its new Fusion Agentic Applications initiative. In parallel, Apollo.io acquired Pocus to strengthen its agentic go-to-market stack, Databricks introduced Lakewatch as an open agentic SIEM platform built on the lakehouse architecture, and Rootstock Software acquired Ascent Solutions to deepen its manufacturing and warehouse execution capabilities.In today's episode, we invited a panel of industry analysts for a live discussion on LinkedIn to analyze current enterprise software stories. We covered many grounds including the direction and roadmaps of each enterprise software vendors. Finally, we analyzed future trends and how they might shape the enterprise software industry.Video: https://www.youtube.com/watch?v=ksS15kccXPcQuestions for Panelists?
Privileged Access Management has outgrown the vault. In this episode, Matthias sits down with lead analyst Alejandro Leal, author of KuppingerCole's newly released PAM Leadership Compass, to explore how the definition of privilege itself has changed, what NHIs and agentic AI mean for PAM, and why deployment sovereignty is now a boardroom conversation. Key Topics: ✅ How the definition of "privilege" has shifted from admin accounts to dynamic runtime identity capabilities✅ PAM convergence with IGA, CIEM, ITDR, SIEM, and SOAR — the end of the standalone PAM product✅ Non-Human Identities (NHIs) and agentic AI: the silent accumulation of machine privilege✅ Just-in-time access: the gap between concept and operational reality✅ Deployment sovereignty: who controls the keys to the kingdom — SaaS, on-prem, or hybrid?✅ AI and ML in PAM: separating genuine innovation from marketing inflation "Most enterprises can tell you the number of employees they have — very few can tell you the number of machine identities." If that sounds familiar, this episode is for you.
In this episode, Raghu Nandakumara sits down with two heavyweights in cybersecurity: Dr. Anton Chuvakin (Google Cloud) and Erik Bloch (Illumio), for a candid, often funny, and occasionally sobering look at why detection and response keeps fighting the same battles it was fighting 20 years ago. From the birth of SIEM and the coining of "EDR," to the short-lived reign of XDR, to today's AI hype cycle, Anton and Erik trace the full arc of the industry's evolution and interrogate why, despite decades of tooling investment, the fundamental outcomes haven't changed. Alert fatigue, signal-to-noise ratios, and the needle-in-the-haystack problem remain as stubborn as ever –and the slides security teams are building in 2025 look suspiciously like the ones from 2003. Raghu, Anton, and Erik discuss: Why the SOC still largely runs on a 1990s operating model and what it would actually take to change that How compliance pulled SIEM away from detection for over a decade and why that hangover still lingers Why a handful of engineering-led organizations (Google, Netflix, a European bank) have cracked the code while nearly everyone else keeps applying band-aids The pharmaceutical industry analogy that explains why security startups keep building band-aids instead of solving root causes What MDRs are doing right and why enterprise SOCs have no incentive to learn from them Why AI is accelerating tooling but, for some organizations, actually slowing down the harder transformation work How securing AI is repeating the exact same mistakes made in the early days of cloud Stay connected with our host Raghu on LinkedIn For more information about Illumio, check out our website at illumio.com
Send us Fan MailAI agents are landing in production faster than most security teams can track them, and the scariest part is how normal they can look. When an autonomous agent runs the same workflow 10,000 times, your SIEM and EDR may see “nothing to worry about” even while the agent quietly drifts outside its intended scope. That is the core AI governance problem we tackle, through the lens of CISSP thinking and real security leadership.We walk through what is driving the mess: board-level pressure, AI FOMO, and the dangerous habit of treating AI agents like old-school automation. Then we get concrete. We talk about why many enterprises still lack an inventory of AI agents, why traditional security tooling is tuned for human behaviour anomalies, and what it actually takes to be audit-ready. We cover practical governance frameworks like tiered autonomy, why observability is more than collecting output logs, and how to design decision-path tracing with execution records and decision logs you can act on.To make it actionable for exam prep and day-to-day work, I close with CISSP-style practice questions on the exact scenarios you will face: detection gaps, human approval bottlenecks, least privilege for agents, proving decisions during audits, and architecting platforms that balance operational efficiency with risk management. If you are serious about passing, I also share how my CISSP Sprint cohort is structured to force momentum, including booking your exam date early.Subscribe for weekly CISSP-focused training, share this with a teammate building AI workflows, and leave a review so more security pros can find the show. What part of AI agent governance is your biggest blind spot right now?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-448
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Show Notes: https://securityweekly.com/bsw-448
Over the last decade, cybersecurity heavily invested in EDR, XDR, SIEM, telemetry, and SOC-driven operations. We stopped asking how to stop attacks and started asking how fast we could detect them. However, Mythos and frontier models have changed that paradigm. How do you detect a -7 day vulnerability? Detection and response cannot keep, so what's the answer? Rob Allen, Chief Product Officer at ThreatLocker, joins Business Security Weekly to discuss why cybersecurity is shifting from detection and response to prevention and enforcement. As attackers accelerate through automation and AI, organizations are revisiting prevention-focused controls. Rob will discuss why organizations need to adopt application allowlisting, Zero Trust, Ringfencing, and policy enforcement to reduce attacker freedom before execution occurs. Prevention-first security is the only way to decrease the AI attack surface. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the leadership and communications segment, What CISOs need to land a board role, The Security Mistakes Being Repeated With AI, When Senior Leaders Lack People Skills, Transformations Fail, and more! Visit https://www.securityweekly.com/bsw for all the latest episodes! Show Notes: https://securityweekly.com/bsw-448
Guest: Matt Gregson, Principal - PwC Cyber Security Topics: What is the state of the art of "agentic SOC" in 2026? Can you describe the most agentic SOC you've seen so far? In your experience, what are the main measurable benefits of AI agents in a SOC and IR? Imagine a 2030 SOC, what do humans do? Tell us more about how you judge if a client SOC is ready for AI and agents? What is the "Ouch" moment where most organizations realize their data isn't ready for that level of autonomy? Should we be more afraid of "AI hallucinations" or "Human fatigue" in the SOC? If a team has an agentic teammate making its own decisions based on emergent reasoning, how do you audit its "thought process"? Everyone loves to talk about "Time Saved," but in an agentic SOC, we care about "Decision Quality." What is the one metric PwC uses to prove that a SOC agent deployment is actually reducing risk? We often hear about "human-agent teaming." Are they still looking at alerts, or are they just approving "Action Plans" generated by the AI? Resources: Video version EP236 Accelerated SIEM Journey: A SOC Leader's Playbook for Modernization and AI EP252 The Agentic SOC Reality: Governing AI Agents, Data Fidelity, and Measuring Success EP264 Measuring Your (Agentic) SOC: Two Security Leaders Walk into a Podcast All SOC and SIEM episodes
Send us Fan MailEight terabytes of stolen schematics is not just a scary number, it is a reminder that cyber risk becomes business risk fast. We start with the Wired report on the Foxconn ransomware attack and unpack what a claim like that could mean in the real world: intellectual property exposure, supply chain disruption, customer impact, and the uncomfortable truth that recovery is only one part of the story when data walks out the door.From there, we switch into CISSP Domain 7 Security Operations mode and work through practical exam-style questions with the “how would this hold up at work” mindset. We break down why live forensics imaging can be the right call during an insider threat investigation, using the order of volatility and the kinds of RAM artifacts that disappear the moment you shut a machine down. We also tackle a Patch Tuesday nightmare scenario where a CVSS 9.8 vulnerability is already being exploited but the change advisory board will not meet for ten days, and we explain why an emergency change process plus compensating controls is the mature security operations answer.We also cover a common privileged access failure where a domain admin uses an elevated account for email and browsing, and how least privilege plus a privileged access workstation (PAW) architecture can prevent a single phish from becoming domain compromise. Finally, we sharpen the fundamentals with an RTO/RPO recovery timeline question and a SIEM brute force threshold miss that illustrates false negatives and the need for better tuning and behavioural baselines.Subscribe for weekly CISSP training, share this with a study partner, and leave a review so more security pros can find the show. What topic do you want me to turn into practice questions next?Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don't miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Vandaag neemt Wessel de honneurs waar als presentator! Samen met Bart blikt hij kort terug op de wedstrijd tegen FC Utrecht, waarbij het venijn in de staart zat, maar niet in positieve zin voor de Amsterdammers. Om de zure nasmaak van de nederlaag weg te spoelen blikken de heren alvast vooruit op het aankomende seizoen, waar Michel nu wel echt de nieuwe trainer lijkt te worden. Wie volgend seizoen waarschijnlijk niet aanwezig is bij de mooiste club van Nederland, is Marijn Beuker. Hij lijkt op weg naar Club Brugge, waar hij afgelopen weekend zelfs al in het stadion gespot is samen met Siem de Jong. In de seizoensbingo blikken we terug op betere tijden, namelijk het kampioensjaar 2010/11. Het jaar van Christian Eriksen, Siem de Jong en Aras Özbiliz, de 3-1 ontknoping tegen FC Twente en AJ Auxerre in de Champions League. Verder bespreken we de transferperikelen rondom oudgedienden Joël Veltman, Daley Blind en Christian Eriksen. Ook vanuit de toekomst is er nieuws. Zo is Reverson voor het eerst opgeroepen voor het Ghanese elftal! Namens Wessel en Bart, veel luisterplezier! (00:00) Intro (01:50) Ajax - FC Utrecht (22:50) Michel lijkt de nieuwe trainer van Ajax te worden (31:45) Nieuws over Marijn Beuker (34:58) De werkwijze van Jordi Cruijff (45:00) Seizoensbingo 2010/11 (53:08) Transfergeruchten (57:45) Jong Ajax Petje AfWil je niks missen en al onze extra content, zoals onder meer de Wedstijdededities en Persconferenties ook meekrijgen? Neem dan een kijkje op petjeaf.com/pantelicpodcastSee omnystudio.com/listener for privacy information.
In this episode, Ken Westin maps AI adoption onto the hero's journey framework, drawing on two decades of security experience to explore how practitioners can move past early resistance, build real fluency with AI tools, and find a working model where humans and AI operate together.Key Topics:Why early AI tools left security teams skeptical and what has genuinely changed since thenHow Ken used AI to accelerate detection engineering without sacrificing analyst oversightWhy AI is best understood as an eager, overconfident intern that still needs supervisionThe importance of hands-on experimentation over passive observation when learning AIHow collaboration and shared prompting practices are shaping how practitioners learnWhy security analysts who engage with AI now will not be left behind as the field evolvesThe case for AI as a tool of empowerment, not replacementAt Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.About Our GuestKen Westin is a Senior Solutions Engineer at LimaCharlie with nearly two decades in the cybersecurity industry. A former startup founder who built tools to track criminal activity, Ken has worked across SIEM, EDR, and detection engineering throughout his career. He also teaches at the college level, where AI and cybersecurity are increasingly intertwined disciplines.Register for Live SessionsJoin us every Friday at 10:30am PT for live, interactive discussions with industry experts. Whether you're a seasoned professional or just curious about the field, these sessions offer an engaging dialogue between our guests, hosts, and you, our audience.Register here: https://limacharlie.io/defender-fridaysSubscribe to our YouTube channel and hit the notification bell to never miss a live session or catch up on past episodes on our website!Sponsored by LimaCharlieThis episode is brought to you by LimaCharlie, the Agentic SecOps Workspace (ASW), where AI agents operate security infrastructure using the same controls and authority as human analysts, with every action visible, governed, and auditable.Why LimaCharlie?Eliminate vendor sprawl and tool complexityDeploy and scale effortlessly on native multi-tenant architectureReduce costs with intelligent data routing and free 1-year retentionBuild custom solutions with 100+ security capabilities on-demandAccelerate response with agentic AI that acts directly within predefined workflowsTry the Agentic SecOps Workspace free: https://limacharlie.ioLearn more: https://docs.limacharlie.ioFollow LimaCharlieSign up for free: https://limacharlie.ioLinkedIn: / limacharlieioX: https://x.com/limacharlieioCommunity Discourse: https://community.limacharlie.com/Host: Maxime Lamothe-Brassard - Founder at LimaCharlieGuest: Ken Westin - Senior Solutions Engineer at LimaCharlie
In the rush to implement AI across the customer experience, are we at risk of creating more digital barriers than we're breaking down?Agility requires a holistic view of the entire digital experience. It's the ability to see not just how individual channels are performing, but how they work together to serve every potential customer, inclusively and intelligently.Today, we're going to talk about what it takes to build that holistic view. We'll explore how brands can unify their performance analytics to move beyond traditional SEO, the dual role of AI in both creating personalized content and ensuring it's accessible, and why inclusivity is becoming one of the most powerful levers for brand growth.To help me discuss this topic, I'd like to welcome Nayaki Nayyar, CEO at Siteimprove. About Nayaki Nayyar Nayaki Nayyar is an accomplished technology executive with a proven track record of driving growth, innovation, and market leadership in enterprise SaaS for over 25 years. As the CEO of Siteimprove, she spearheads the company's vision and strategy, accelerating its market leadership in Agentic Content Intelligence powered by Siteimprove.ai platform. In her prior role as the CEO of Securonix, she guided the company's strategic shift into AI with the launch of Securonix EON, an AI-powered cyber-security platform. Under her leadership, Securonix secured its position in the Gartner Magic Quadrant for SIEM for five consecutive years, driving significant growth and product innovation to address evolving global cybersecurity threats.Nayaki brings deep expertise in scaling businesses organically and through strategic acquisitions. As President and Chief Product Officer at Ivanti, she established the company's cybersecurity and endpoint management strategy, growing revenue from $500M to $1.2B and doubling the total addressable market from $30B to $60B in just two years. She also played a pivotal role in launching the Ivanti Neurons Platform and driving expansion through acquisitions. As BMC Software's President of Digital Service and Operations Management, Nayaki led its transformation into AI-driven enterprise solutions with the BMC Helix suite, a strategic evolution that contributed to BMC's $8.2B exit in 2018.Nayaki serves on the boards of TD Synnex and Corteva Agriscience and is a graduate of the Stanford Executive Program. She holds a B.E. in Mechanical Engineering from Osmania University and an M.S. in Computer Science from the University of Houston. Recognized among the "Top Women in Technology in the U.S." by Technology Magazine in 2022, she is a respected leader shaping the future of enterprise technology in the AI era. Nayaki Nayyar on LinkedIn: https://www.linkedin.com/in/nayakinayyar/ Resources Siteimprove: https://www.siteimprove.com/ The Agile Brand podcast is brought to you by TEKsystems. Learn more here: https://aglbrnd.co/r/2868abd8085a9703 Drive your customers to new horizons at the premier retail event of the year for Retail and Brand marketers. Learn more at CRMC 2026, June 1-3. https://aglbrnd.co/r/d15ec37a537c0d74 We're proud to be a media partner for #MAICON26 - Oct. 13-15! Learn how AI can power your marketing and business and help you grow smarter. Use code AGILE150 to save! https://aglbrnd.co/r/7fe458ced0f04658 Enjoyed the show? Tell us more at and give us a rating so others can find the show at: https://aglbrnd.co/r/faaed112fc9887f3 Connect with Greg on LinkedIn: https://www.linkedin.com/in/gregkihlstromDon't miss a thing: get the latest episodes, sign up for our newsletter and more: https://aglbrnd.co/r/35ded3ccfb6716ba Check out The Agile Brand Guide website with articles, insights, and Martechipedia, the wiki for marketing technology: https://www.agilebrandguide.com The Agile Brand is produced by Missing Link—a Latina-owned strategy-driven, creatively fueled production co-op. From ideation to creation, they craft human connections through intelligent, engaging and informative content. https://www.missinglink.company Hosted on Acast. See acast.com/privacy for more information.
In the rush to implement AI across the customer experience, are we at risk of creating more digital barriers than we're breaking down? Agility requires a holistic view of the entire digital experience. It's the ability to see not just how individual channels are performing, but how they work together to serve every potential customer, inclusively and intelligently. Today, we're going to talk about what it takes to build that holistic view. We'll explore how brands can unify their performance analytics to move beyond traditional SEO, the dual role of AI in both creating personalized content and ensuring it's accessible, and why inclusivity is becoming one of the most powerful levers for brand growth. To help me discuss this topic, I'd like to welcome Nayaki Nayyar, CEO at Siteimprove. About Nayaki Nayyar Nayaki Nayyar is an accomplished technology executive with a proven track record of driving growth, innovation, and market leadership in enterprise SaaS for over 25 years. As the CEO of Siteimprove, she spearheads the company's vision and strategy, accelerating its market leadership in Agentic Content Intelligence powered by Siteimprove.ai platform. In her prior role as the CEO of Securonix, she guided the company's strategic shift into AI with the launch of Securonix EON, an AI-powered cyber-security platform. Under her leadership, Securonix secured its position in the Gartner Magic Quadrant for SIEM for five consecutive years, driving significant growth and product innovation to address evolving global cybersecurity threats.Nayaki brings deep expertise in scaling businesses organically and through strategic acquisitions. As President and Chief Product Officer at Ivanti, she established the company's cybersecurity and endpoint management strategy, growing revenue from $500M to $1.2B and doubling the total addressable market from $30B to $60B in just two years. She also played a pivotal role in launching the Ivanti Neurons Platform and driving expansion through acquisitions. As BMC Software's President of Digital Service and Operations Management, Nayaki led its transformation into AI-driven enterprise solutions with the BMC Helix suite, a strategic evolution that contributed to BMC's $8.2B exit in 2018.Nayaki serves on the boards of TD Synnex and Corteva Agriscience and is a graduate of the Stanford Executive Program. She holds a B.E. in Mechanical Engineering from Osmania University and an M.S. in Computer Science from the University of Houston. Recognized among the "Top Women in Technology in the U.S." by Technology Magazine in 2022, she is a respected leader shaping the future of enterprise technology in the AI era. Nayaki Nayyar on LinkedIn: https://www.linkedin.com/in/nayakinayyar/ Resources Siteimprove: https://www.siteimprove.com/ The Agile Brand podcast is brought to you by TEKsystems. Learn more here: https://aglbrnd.co/r/2868abd8085a9703 Drive your customers to new horizons at the premier retail event of the year for Retail and Brand marketers. Learn more at CRMC 2026, June 1-3. https://aglbrnd.co/r/d15ec37a537c0d74 We're proud to be a media partner for #MAICON26 - Oct. 13-15! Learn how AI can power your marketing and business and help you grow smarter. Use code AGILE150 to save! https://aglbrnd.co/r/7fe458ced0f04658 Enjoyed the show? Tell us more at and give us a rating so others can find the show at: https://aglbrnd.co/r/faaed112fc9887f3 Connect with Greg on LinkedIn: https://www.linkedin.com/in/gregkihlstromDon't miss a thing: get the latest episodes, sign up for our newsletter and more: https://aglbrnd.co/r/35ded3ccfb6716ba Check out The Agile Brand Guide website with articles, insights, and Martechipedia, the wiki for marketing technology: https://www.agilebrandguide.com The Agile Brand is produced by Missing Link—a Latina-owned strategy-driven, creatively fueled production co-op. From ideation to creation, they craft human connections through intelligent, engaging and informative content. https://www.missinglink.company
Are tech industries selling us a problems they invented?Ryan Clarque, CSO at Black Rifle Coffee Company, doesn't flinch at the big provocations. When Claude's Mythos model showed up in every LinkedIn feed promising a software apocalypse, Ryan's take was blunt: the basics were broken before Mythos, and they'll still be broken after it. The real question about a powerful AI model, it's whether you've built a program capable of doing anything about them when it does.But the conversation doesn't stop at hype-busting. Ryan has quietly done something the industry insists can't be done: built a lean, two-person security operation that ditched the big-ticket SIEM vendors, took control of its own telemetry, and outperformed programs with ten times the headcount and budget. When one of those vendors found out, they sent their "heavy hitter" to prove Ryan wrong, who left agreeing Ryan didn't need them.What emerges is a portrait of a practitioner who learned to distinguish progress from movement — and who thinks most of the industry is confusing the two. The procurement cycle, the Gartner roadmap, the sequence of investments you're told you must make: Ryan's argument is that inertia dressed up as strategy has left small security teams demoralized and over-leveraged, and that the fix is less about budget and more about the willingness to build your own way out.And then, at the end of a week of planes and conferences, Ryan says something that reframes all of it. The reason he doesn't chase the car or the watch or the title isn't asceticism — it's that working in security means observing the worst of what people do to each other, and the only way to stay functional is to invest hard in what actually holds. Time. Trust. People who remember how you made them feel.Mentioned: Cal Newport on Mythos vs other LLMs in finding software vulnerabilities
Guests: Eric Foster, CEO, Tenex.AI Bashar Abouseido, President, Tenex.AI Topics: "10X SOC" sounds great. But for an organization stuck in "SIEM 1.0" with poor data quality and manual workflows, is "AI-native MDR" a "leapfrog" opportunity or a recipe for disaster? We've seen the rise of "Decoupled SIEM" and security data lakes. Does a "Modern SIEM" even need to exist if an MDR platform has an agentic layer doing the heavy lifting? You've argued for AI-native over AI-bolted-on. For an end user, what are the tangible differences of using "AI inside a legacy SIEM" versus using an "AI-native separate product"? What is the one task you thought AI would handle by now that still requires a senior human analyst to step in? If a CISO is using an AI MDR, "Mean Time to Detect" (MTTD) starts to look like a vanity metric because the machine is instant. What is the new golden metric for an AI-powered SOC? Is it "Time to Context," "Reduction in Human Toil," or something else? How do you help a skeptical SOC Manager—who has been burned by false positives for a decade—trust an autonomous agent to perform a "containment" action at 3:00 AM? Resources: EP227 AI-Native MDR: Betting on the Future of Security Operations? EP10 SIEM Modernization? Is That a Thing? The original "10X" paper "Autonomic Security Operations: 10X Transformation of the Security Operations Center"
The security industry has spent years debating which tools to buy. Impetum is asking a different question: are the tools you already have actually working? Founded by incident responders who saw the same failures across hundreds of breaches, Impetum built the Persistent Purple Team platform to simulate advanced threat actors inside customer environments on a continuous monthly basis -- not as a one-time engagement, but as an ongoing relationship built around real data, custom TTPs, and a measurable Threat Resilience Score. Matt Stewart and Alex Grohmann spoke with Sean Martin and Marco Ciappelli at RSAC Conference 2026 about what they are hearing on the show floor: agentic AI is accelerating the speed of compromise and exposing vulnerabilities in legacy systems that have been dormant for decades. Against that backdrop, the value of knowing -- not assuming -- that your detection and response capabilities hold up becomes critical. The platform builds that knowledge through live-fire exercises using an organization's own data, validating patch management, XDR, SIEM tuning, and post-compromise detection in a way no annual pen test can. The conversation also touched on the structural talent problem agentic AI is creating inside SOCs. As AI fills the level one analyst role, the pipeline for developing level two analysts and incident responders is narrowing. Impetum sees persistent purple teaming as the training ground that closes that gap -- giving existing teams the repeated, realistic practice they need to respond with confidence when an actual breach begins. Impetum targets mid-size organizations that have the right security tools but lack the budget, bandwidth, and access to industry events to keep those tools continuously validated against evolving attack paths. For those teams, the platform delivers something an annual report cannot: a documented, ongoing record of what works, what does not, and where the program is heading. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Matt Stewart, Co-Founder, Impetum Alex Grohmann, Co-Founder, Impetum LinkedIn: https://www.linkedin.com/in/alexandergrohmann/ RESOURCES Impetum / Persistent Purple Team: https://www.persistentpurpleteam.com ITSPmagazine RSAC Conference 2026 coverage: https://www.itspmagazine.com/rsac-2026-conference-san-francisco-usa-cybersecurity-event-infosec-conference-coverage Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Matt Stewart, Alex Grohmann, Impetum, Persistent Purple Team, Remedium Security, Sean Martin, RSAC Conference 2026, brand spotlight, brand story, brand marketing, marketing podcast, purple teaming, continuous security validation, threat resilience, CISO, security operations, SOC, red team, blue team, incident response, agentic AI, MITRE ATT&CK, penetration testing, cybersecurity Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 92: Costin walks through real-world ransomware incident response while Juanito makes the case for AI-generated operating systems that never run anyone else's code. Plus, debates on whether vulnerability research is cooked, why nobody should pay ransoms, and what the security industry looks like after the massive AI flood. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. 0:00 – Introductory banter 2:00 – Costin's ransomware incident response work 3:30 – How attackers break in: Fortinet vulnerabilities everywhere 6:30 – Hunting for ransomware decryption keys 9:00 – Breaking into ransomware C2s and monitoring leak sites 12:00 – The ransom payment debate: should you ever pay? 16:00 – Why "don't pay the ransom" is overgeneralized 21:00 – How ransomware gangs price their demands 24:00 – The AI-pilling of the security industry 28:30 – Nicholas Carlini, Ptacek, and "vulnerability research is cooked" 35:00 – Towards a generative-first operating system 41:00 – Code factories, trusted computing, and killing dependencies 48:00 – Microsoft and Apple's AI positioning 56:00 – Chris St. Myers' "Cognitive Rust Belt" essay 1:18:00 – Choice, The Matrix, and the illusion of control 1:38:00 – Supply chain attacks, North Korea, and dependency sprawl
The security operations center is under pressure from every direction -- rising alert volumes, fragmented data environments, and a skills gap that no amount of hiring fully closes. At RSAC Conference 2026, Monzy Merza of Crogl sat down with Sean Martin and Marco Ciappelli to talk about what the AI-enabled SOC actually looks like when it is working at enterprise scale. Crogl recently published the State of the AI SOC report, a survey of more than 600 organizations. The headline finding: nearly 40% of alerts go completely unattended. Not triaged. Not escalated. Just missed. The report also found that a large share of respondents rank the security of an AI system above its raw capability -- trust before performance. Merza says the goal of the report was part data, part demystification, and part empathy building -- giving security leaders permission to recognize that everyone is dealing with the same problems. Crogl's knowledge engine is built on a foundational premise: data is fragmented in the enterprise, and that is not going to change. Rather than requiring data normalization before analysis, Crogl builds an enterprise semantic knowledge graph that maps relationships across data lakes, SIEMs, and SOAR platforms, wherever the data lives. Analysts no longer need to navigate schemas or query languages. Crogl handles the investigation and surfaces what matters. Merza describes two compressor effects his customers experience. A competency compressor allows any analyst to draw on multiple data lakes at once. A domain knowledge compressor lets Crogl work across alert types -- phishing, endpoint, and beyond -- rather than routing each to a specialist. The result is a team that operates well above its apparent headcount. One customer example: a CISA advisory that would take hours to manually parse can be uploaded into Crogl and assessed across the enterprise footprint -- IOC mapping and detection coverage -- in sub-hours. The same logic extends to compliance, where audit data calls that once required manual query-by-query execution can now be executed by Crogl against a full 500-query data call at once. On the jobs question, Merza takes a clear position: AI will create more security jobs, not fewer. Every new AI deployment is a new attack surface. Every new footprint needs to be defended. The repetitive tier-one work is going away -- but the volume of meaningful security work is expanding and the entry level is rising. The organizations getting ahead of this are already standing up AI review boards and putting security capability at the center of how they evaluate new AI tools. This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight GUEST Monzy Merza, Co-Founder and CEO, Crogl LinkedIn: https://www.linkedin.com/in/monzymerza RESOURCES State of the AI SOC Report (free download): https://www.crogl.com Crogl: https://www.crogl.com AI SOC Summit: https://aisocsummit.com Are you interested in telling your story? ▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full ▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight ▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight KEYWORDS Monzy Merza, Crogl, Sean Martin, Marco Ciappelli, brand spotlight, brand marketing, marketing podcast, brand story, AI SOC, security operations center, SOC automation, AI in cybersecurity, alert fatigue, security data lakes, SIEM integration, enterprise knowledge graph, threat intelligence, CISA advisory, Volt Typhoon, RSAC Conference 2026, RSAC 2026, cybersecurity AI, autonomous investigation, SOC analysts, security workforce, CISO strategy Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Security Conversations: Jeremy Bannon, founder/CEO of The Cyber Health Company, joins Ryan Naraine to discuss why executive personal cybersecurity is a growing blind spot for organizations, and real-world incidents where personal compromises became corporate crises. Plus, why CISOs struggle to secure the C-suite's personal lives, and how a healthcare-inspired model (complete with risk scores, care plans, and concierge support) can help companies close the gap. 0:00 — Introduction to The Cyber Health Company 1:00 — Why personal security is a blind spot for organizations 2:00 — Real examples: Disney hack, Instagram compromise, productivity loss 6:50 — Executives circumventing IT policy and Shadow-AI 8:43 — Digital immunity: resilience and incident response readiness 10:25 — The healthcare model for cybersecurity communication 12:14 — How the Cyber Health Score and risk coefficient work 15:34 — OSINT intake: why your social security number isn't private 17:26 — The state of executive security hygiene and the concierge model 35:00 — AI, deepfakes, and the scaling of commodity attacks
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 91: This week we dig into Google's new cyber threat disruption unit announced at RSAC, Kaspersky confirming Coruna is a direct evolution of Operation Triangulation, and a cascading supply chain compromise that chained through LiteLLM, Trivy, and Checkmarx into thousands of software pipelines. Plus, VCs and the breathless AI hype, Apple's iOS 26.4 and silent patches, the FCC's ban on foreign-made routers, and Symantec catching an APT looking for Chinese military data. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu. 0:00 Intro & Pre-Show Banter 3:08 JAGS in San Francisco: RSAC week recap 6:05 Google Launches Cyber Disruption Unit — What's Actually New? 13:43 Why Separate Disruption Units Matter: ROI & Budget Justification 29:11 Haroon Meer's RSA Reality Check: The AI Hype Machine 32:37 The VC Ponzi Cycle & How Easy Money Hollowed Out Cybersecurity 47:32 ENT.ai & Tenex AI Hackathon at RSAC 53:08 Kaspersky Links Corona Exploit Kit to Operation Triangulation 1:08:09 Trenchant Cleanup & Lessons from Equation Group Burns 1:19:31 Apple iOS Patches, Hong Kong Device Passcode Law 1:27:53 Handala Hacks FBI Director Kash Patel's Personal Gmail 1:37:32 LeakBase Admin "Chucky" Arrested in Russia — FSB Gets the Data 1:45:38 Supply Chain Attacks: TeamPCP Hits LiteLLM & Trivy 2:04:34 FCC Bans Foreign-Made Routers — But What Do We Buy?
SaaS Scaled - Interviews about SaaS Startups, Analytics, & Operations
Today, we're joined by Evan Powell, Founding CEO of DeepTempo, a pioneer in behavioral threat detection powered by deep learning. We talk about:The cybersecurity problems – and solutions– resulting from AIPossible continued existence of huge software companies generating high revenuesThe source of SaaS value: The AI model or the software/code?How to price SaaS apps when most users are AI agentsThe proliferation of custom, homegrown software in enterprises
Guest: Raffael Marty, Operating Advisor, a SIEM legend since 1999 Topics: You argue that declaring existing SIEM being obsolete is a "marketing slogan" rather than a true thesis. What is the real pain point and the actual gap in traditional SIEMs as opposed to the more sensational claims? You highlight that "correlation, state, timelines, and real-time detection require locality," making centralization a necessary trade-off. Can a truly federated or decoupled SIEM architecture achieve the same fidelity and real-time performance for complex, stateful detections as a centralized one? You call the rise of independent security data pipelines the "SIEM Trojan Horse." How quickly is this abstraction layer turning SIEM into a "swappable" component, and what should SIEM vendors have done differently years ago to prevent this market from existing? This "AI SOC" thing, is this even real? Is AI in a SOC a better label? Do you think major SIEM vendors will own this very soon, like they did with UEBA and SOAR? If volume-based pricing is flawed because it penalizes good security hygiene, what is a better SIEM pricing model that fairly addresses compute, enrichment, and retention costs without just shifting the volume cost to unpredictable query charges? You question the idea that startups can find a better way to release detection rules than large vendors with significant content teams. What metrics should security leaders use to evaluate the quality of a vendor's detection engineering (DE) output beyond just coverage numbers? Can AI fix DE? Resources: Video version The SIEM Maturity Framework: A Practical Scoring Tool for Security Analytics Platforms and raffy.ch/SIEM/ The Gaps That Created the New Wave of SIEM and AI SOC Vendors How AI Impacts the Cyber Market and The Future of SIEM Why Venture Capital Is Betting Against Traditional SIEMs EP236 Accelerated SIEM Journey: A SOC Leader's Playbook for Modernization and AI EP234 The SIEM Paradox: Logs, Lies, and Failing to Detect EP125 Will SIEM Ever Die: SIEM Lessons from the Past for the Future Decoupled SIEM: Brilliant or Stupid? Decoupled SIEM: Where I Think We Are Now?
(Presented by TLPBLACK: High-fidelity threat intelligence and research tools for modern security teams. From curated Passive DNS and real-time C2 monitoring to actionable IOC feeds and daily malware samples, we help defenders detect, hunt, and disrupt threats faster, with seamless integration into SIEM and SOAR workflows.) Three Buddy Problem - Episode 89: We discuss Iran hacktivist group 'Handala' wiper attacks against US medical device maker Stryker, Microsoft Intune MDM tool abuse, and whether Iran's cyber retaliation is as scary as the headlines suggest. Plus, ESET's discovery that Russia's APT28 original implant developers are back after years of silence, Dutch intelligence warnings on Russian campaigns targeting Signal and WhatsApp accounts, Apple finally patching Coruna exploit kit vulnerabilities for older iPhones, and Google sharing Coruna samples that raise new questions about the exploit kit's proliferation chain. Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
Alan Lucas always wanted to be an architect or a firefighter — as CISO of Worldstream and Greenhouse Datacenters, he has become both. In this episode, he joins host Steve Moore to explore leading cybersecurity at the intersection of design and crisis response.Alan traces his path from Fox-IT through a Dutch cryptocurrency exchange where he arrived post-breach to an organization under near-constant attack from nation-state threat actors. Leading a technically sophisticated but security-anxious leadership team, he learned the lasting power of transparency and directness — and his most memorable measure of success was not a technical control, but a CTO who finally slept through the night.The conversation goes deep into crisis communication. Alan and Steve discuss how the industry has matured from reflexive silence around breaches to embracing transparency as a trust-building tool, the danger of well-meaning legal edits that send customers chasing the wrong narrative, and why the CISO should hold final review over all public incident communications. He also shares his Security Champions Program, tabletop exercise design, and why knowing who to call in a crisis must be mapped out before that crisis arrives.Alan also covers his volunteer work with the DIVD, coaching ethical hackers and supporting responsible disclosure worldwide — an extension of his belief that security, done well, creates trust and enables growth for everyone.The episode closes on "bouncing forward" — the idea that true resilience means using every incident as a forcing function for improvement, not just a return to baseline. Alan frames lessons learned as the most important resilience KPI a security team can own. A masterclass in leading through both calm and chaos. Key Topics• The architect-and-firefighter mindset: building security programs while fighting live fires• Alan's career path from Fox-IT (MSSP) to post-breach CISO at a cryptocurrency exchange• Leading security post-breach — and what "sleeping well again" actually means• The unique threat landscape facing cryptocurrency companies, including nation-state adversaries• The Dutch Institute for Vulnerability Disclosure (DIVD): coordinated, ethical vulnerability disclosure worldwide• Mentoring young ethical hackers: communication, confidence, and responsible disclosure process• Crisis communication: balancing transparency with operational security during active incidents• Why legal edits to breach notifications can mislead customers and create dangerous distractions• The CISO's role as final reviewer of all incident communications• Security Champions Programs: bridging the gap between security and non-technical departments• Tabletop exercise design: running effective simulations in under an hour with non-technical staff• Writing the breach notification letter before the breach happens• Bouncing forward, not bouncing back: using lessons learned as a resilience KPI• Security as a business enabler: positioning the CISO role for organizational growth and confidenceGuest BioAlan Lucas is CISO at Worldstream and Greenhouse Datacenters, two of the Netherlands' leading cloud and data center infrastructure providers. With over a decade of cybersecurity experience, he leads security strategy for mission-critical IT and cloud environments. Prior roles include Fox-IT (MSSP) and LiteBit, a Dutch cryptocurrency exchange where he served as CISO post-breach. Alan also volunteers as a coach at the Dutch Institute for Vulnerability Disclosure (DIVD), mentoring ethical hackers and supporting responsible disclosure globally. He is passionate about security as a catalyst for innovation — and about building a safer digital society, one step at a time.LEARN MORE:
Spencer Siem is a New Mexico–based fly fishing guide known for his deep knowledge of Southwestern waters and his connection to the Feather Thief legacy. Blending technical precision with a reverence for fly-tying history, Spencer approaches guiding as both craft and storytelling. His work reflects a respect for tradition, a curiosity for innovation, and a quiet dedication to passing the culture of fly fishing forward. In this episode of Anchored, we learn more about his story. Looking to go deeper with your learning? Come see what we've been working on at AnchoredOutdoors.com. We've built a library of 30 in-depth, sequentially organized Masterclasses taught by past guests of this podcast — and we've watched over 1,000 members grow their confidence and skills on the water. Want to check it out for free? No money down, no strings attached. Just head to anchoredoutdoors.com/premium-insiders/ Anchored listeners can get 10% off their first order with Skwala by using the code “anchored10” at check out. See for yourself at skwalafishing.com Learn more about your ad choices. Visit megaphone.fm/adchoices